General Info

File name

Office Converter Pack.exe

Full analysis
https://app.any.run/tasks/e0dca1d1-f79b-4952-8739-ae8931863913
Verdict
Malicious activity
Analysis date
10/9/2019, 17:22:48
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
MD5

c16fe4a973855b9a3944cb035c0dd82a

SHA1

6fd4cde3461f634359bfe7dcf837674f51b6752f

SHA256

6412fa3dce709ff735b52d21bdaf5ca98ca05f86e2af9e5b8ee03b511366635f

SSDEEP

196608:6FQGLMGReuFcN5WKYf0Qm9PmxS1h++L83b6TxcFug9QFo:E4huFEbYvwAi03bh8/K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes the autorun value in the registry
  • Office Converter Pack.exe (PID: 3940)
Application was dropped or rewritten from another process
  • SETUP.EXE (PID: 3076)
Executable content was dropped or overwritten
  • Office Converter Pack.exe (PID: 3940)
  • msiexec.exe (PID: 2720)
  • OSE.EXE (PID: 3452)
  • msiexec.exe (PID: 3728)
Starts Microsoft Installer
  • SETUP.EXE (PID: 3076)
Executed as Windows Service
  • OSE.EXE (PID: 3452)
  • vssvc.exe (PID: 2240)
Creates COM task schedule object
  • msiexec.exe (PID: 3728)
Creates files in the Windows directory
  • msiexec.exe (PID: 3728)
Executed via COM
  • DrvInst.exe (PID: 3416)
Searches for installed software
  • msiexec.exe (PID: 3728)
Application launched itself
  • msiexec.exe (PID: 3728)
Reads Microsoft Office registry keys
  • MsiExec.exe (PID: 3380)
  • MsiExec.exe (PID: 3312)
Creates a software uninstall entry
  • msiexec.exe (PID: 3728)
  • MsiExec.exe (PID: 3312)
Creates files in the program directory
  • msiexec.exe (PID: 3728)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 2240)
Manual execution by user
  • cmd.exe (PID: 3012)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Microsoft Update - Self Extracting Cabinet (82.1%)
.exe
|   Win32 Executable MS Visual C++ (generic) (7.5%)
.exe
|   Win64 Executable (generic) (6.6%)
.dll
|   Win32 Dynamic Link Library (generic) (1.5%)
.exe
|   Win32 Executable (generic) (1%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2001:08:18 03:42:57+02:00
PEType:
PE32
LinkerVersion:
7
CodeSize:
34816
InitializedDataSize:
7439360
UninitializedDataSize:
null
EntryPoint:
0x5a5e
OSVersion:
5.1
ImageVersion:
5.1
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
11.0.5614.0
ProductVersionNumber:
11.0.5614.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
Microsoft Office 2003 Resource Kit Self-Extracting Installer
FileVersion:
11.0.5614
InternalName:
ork.exe
LegalCopyright:
© Microsoft Corporation. All rights reserved.
OriginalFileName:
ork.exe
ProductName:
Microsoft Office 2003 Resource Kit
ProductVersion:
11.0.5614

Screenshots

Processes

Total processes
51
Monitored processes
12
Malicious processes
1
Suspicious processes
1

Behavior graph

+
drop and start start office converter pack.exe no specs office converter pack.exe setup.exe no specs ose.exe msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs cmd.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3588
CMD
"C:\Users\admin\AppData\Local\Temp\Office Converter Pack.exe"
Path
C:\Users\admin\AppData\Local\Temp\Office Converter Pack.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
Microsoft Office 2003 Resource Kit Self-Extracting Installer
Version
11.0.5614
Modules
Image
c:\users\admin\appdata\local\temp\office converter pack.exe
c:\systemroot\system32\ntdll.dll

PID
3940
CMD
"C:\Users\admin\AppData\Local\Temp\Office Converter Pack.exe"
Path
C:\Users\admin\AppData\Local\Temp\Office Converter Pack.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Office 2003 Resource Kit Self-Extracting Installer
Version
11.0.5614
Modules
Image
c:\users\admin\appdata\local\temp\office converter pack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advpack.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\setup.exe

PID
3076
CMD
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\SETUP.EXE /iexpress CDCACHE=2
Path
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\SETUP.EXE
Indicators
No indicators
Parent process
Office Converter Pack.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Setup Bootstrapper
Version
11.0.5510
Modules
Image
c:\users\admin\appdata\local\temp\ixp000.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\ose.exe
c:\windows\system32\msiexec.exe

PID
3452
CMD
"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Path
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Office Source Engine
Version
14.0.4730.1010
Modules
Image
c:\program files\common files\microsoft shared\source engine\ose.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll

PID
2720
CMD
"C:\Windows\system32\msiexec.exe" /I "C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\ORK.MSI" CDCACHE=2 LAUNCHEDFROMSETUP=1 SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\IXP000.TMP\ SETUPEXENAME=SETUP.EXE /lpiwaeo "C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001)_Task(0001).txt" STANDALONEOSE="C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE" CDCACHE="2" DELETABLECACHE="1" LOCALCACHEDRIVE="C" DWSETUPLOGFILE="C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt" DWMSILOGFILE="C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001)_Task(0001).txt"
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
SETUP.EXE
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\msihnd.dll
c:\windows\system32\comdlg32.dll
c:\progra~1\micros~1\office14\outlook.exe
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\source engine\ose.exe
c:\windows\system32\riched20.dll

PID
3728
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\source engine\ose.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll

PID
3380
CMD
C:\Windows\system32\MsiExec.exe -Embedding DFADD9E95276F31CB246B71885DB2EB6 C
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\msi2e94.tmp
c:\users\admin\appdata\local\temp\msi2f02.tmp
c:\users\admin\appdata\local\temp\msi2f22.tmp
c:\users\admin\appdata\local\temp\msi2f33.tmp
c:\users\admin\appdata\local\temp\msi2f43.tmp
c:\users\admin\appdata\local\temp\msi2f54.tmp
c:\users\admin\appdata\local\temp\msi4732.tmp
c:\users\admin\appdata\local\temp\msi4743.tmp
c:\users\admin\appdata\local\temp\msi55ac.tmp
c:\users\admin\appdata\local\temp\msi55bc.tmp
c:\users\admin\appdata\local\temp\msi5bd8.tmp
c:\users\admin\appdata\local\temp\msi5be8.tmp

PID
2240
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
3416
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "00000390" "000005CC"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
3312
CMD
C:\Windows\system32\MsiExec.exe -Embedding 704E1349A4177443310EB23203175081
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi96a5.tmp
c:\windows\installer\msi98c9.tmp
c:\windows\installer\msi99e4.tmp
c:\windows\installer\msia1d6.tmp
c:\windows\installer\msia35d.tmp
c:\windows\installer\msia38d.tmp

PID
3296
CMD
C:\Windows\system32\MsiExec.exe -Embedding D6095E7E85A35C3CB1A50C9089005222 M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msia119.tmp

PID
3012
CMD
"C:\Windows\system32\cmd.exe"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
1126
Read events
557
Write events
559
Delete events
10

Modification events

PID
Process
Operation
Key
Name
Value
3940
Office Converter Pack.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
wextract_cleanup0
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
3076
SETUP.EXE
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls\-1001
3076
SETUP.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls
MainTaskName
Microsoft Office 2003 Resource Kit
3076
SETUP.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls\0
TaskName
Microsoft Office 2003 Resource Kit
3076
SETUP.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls\0
Path
C:\Windows\system32\msiexec.exe
3076
SETUP.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls\0
CmdLine
/I C:\Users\admin\AppData\Local\Temp\IXP000.TMP\ORK.MSI CDCACHE="2" LAUNCHEDFROMSETUP="1" SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\IXP000.TMP\" SETUPEXENAME="SETUP.EXE"
3076
SETUP.EXE
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls\0
3076
SETUP.EXE
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls
3076
SETUP.EXE
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9
Type
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9
DefaultDrive
3
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9
Priority
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
Products
{90240409-6000-11D3-8CFE-0150048383C9}
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
IExpress
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Sources\90240409-6000-11D3-8CFE-0150048383C9
Path
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Sources\90240409-6000-11D3-8CFE-0150048383C9
Priority
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
RelativeCachePath
FILES\PFILES\ORKTOOLS\ORK11\ORK.CHM
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
RelativeSourcePath
ORK.CHM_1033
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Priority
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Signed
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
HashType
32771
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Hash
DD4F9BB9FDA40ABEB5EBC0F95FFB3593
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Size
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Progress
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
LastAttemptHigh
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
LastAttemptLow
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
LastError
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateCache
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateExtract
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateVerify
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateAvailable
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
ORK.CHM_1033
nocleanup
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
ORK.CHM_1033
nocleanupC:{90240409-6000-11D3-8CFE-0150048383C9}
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
LastError
1073741834
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateCache
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateExtract
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateVerify
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateAvailable
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
RelativeCachePath
ORK.MSI
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
RelativeSourcePath
ORK.MSI
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Priority
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Signed
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
HashType
32771
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Hash
BDAE5C55256BEDC65AED3FDC17C506DC
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Size
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Progress
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
LastAttemptHigh
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
LastAttemptLow
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
LastError
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateCache
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateExtract
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateVerify
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateAvailable
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
ORK.MSI
nocleanup
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
ORK.MSI
nocleanupC:{90240409-6000-11D3-8CFE-0150048383C9}
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
LastError
1073741834
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateCache
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateExtract
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateVerify
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateAvailable
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
RelativeCachePath
FILES\SETUP\OSE.EXE
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
RelativeSourcePath
OSE.EXE
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Priority
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Signed
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
HashType
32771
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Hash
7A56CF3E3F12E8AF599963B16F50FB6A
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Size
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Progress
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
LastAttemptHigh
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
LastAttemptLow
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
LastError
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateCache
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateExtract
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateVerify
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateAvailable
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
OSE.EXE
nocleanup
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
OSE.EXE
nocleanupC:{90240409-6000-11D3-8CFE-0150048383C9}
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
LastError
1073741834
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateCache
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateExtract
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateVerify
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateAvailable
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
RelativeCachePath
ORK.CAB
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
RelativeSourcePath
ORK.CAB
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Priority
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Signed
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
HashType
32771
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Hash
3213B9C7061E1485747D3CEE0091AB9C
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Size
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Progress
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
LastAttemptHigh
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
LastAttemptLow
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
LastError
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateCache
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateExtract
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateVerify
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateAvailable
0
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Size
25594
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
Progress
25594
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
LastAttemptHigh
30768821
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
LastAttemptLow
2004899484
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateCache
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
ORK.CAB
nocleanup
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateVerify
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CHM_1033
StateAvailable
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Properties
ORK.CAB
nocleanupC:{90240409-6000-11D3-8CFE-0150048383C9}
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Size
535552
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
Progress
535552
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
LastAttemptHigh
30768821
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
LastAttemptLow
2005055734
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateCache
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateVerify
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.MSI
StateAvailable
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Size
89136
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
Progress
89136
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
LastAttemptHigh
30768821
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
LastAttemptLow
2005211984
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateCache
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateVerify
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE
StateAvailable
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
LastError
1073741834
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateCache
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateExtract
2
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateVerify
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateAvailable
1
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Size
7123447
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
Progress
7123447
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
LastAttemptHigh
30768821
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
LastAttemptLow
2095368234
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateCache
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateVerify
4
3452
OSE.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90240409-6000-11D3-8CFE-0150048383C9\Resources\ORK.CAB
StateAvailable
4
2720
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
65
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
40000000000000007E0C727FB57ED501900E000094050000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
40000000000000007E0C727FB57ED501900E000094050000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
24
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
4000000000000000CC7EC57FB57ED501900E000094050000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000CC7EC57FB57ED501900E00006C0F0000E8030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
400000000000000016B09980B57ED501900E00006C0F0000E8030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
4000000000000000A6585686B57ED501900E000094050000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
4000000000000000A6585686B57ED501900E000094050000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
4000000000000000D0CD6B86B57ED501900E000094050000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
400000000000000054A58386B57ED501900E0000180D0000E9030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
40000000000000004006A586B57ED501900E0000180D0000E9030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
40000000000000009A68A786B57ED501900E00002C0D0000F9030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
40000000000000005C54B386B57ED501900E00002C0D0000F9030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
40000000000000001019B886B57ED501900E0000940500000A040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
40000000000000007020C387B57ED501900E0000700B00000A040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
40000000000000007020C387B57ED501900E000094050000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
40000000000000007020C387B57ED501900E000094050000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
24
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
7E0C727FB57ED501
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
900E000040EA5678B57ED501
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
DD86D8A69EBE43A3D63574F257FC16AAC6AEDE6FF3567F10C4B346BED83EC26C
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\1092ae.ipi
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\1092af.rbs
30768829
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\1092af.rbsLow
3934533616
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9040420956516A644AB9FBE016932182
9040420900063D11C8EF10054038389C
02:\Software\Microsoft\Office\11.0\Delivery\{90240409-6000-11D3-8CFE-0150048383C9}\CDCache
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90404209C9C34C24084AA70FC42A3C9D
9040420900063D11C8EF10054038389C
02:\Software\Microsoft\Office\11.0\Delivery\{90240409-6000-11D3-8CFE-0150048383C9}\DownloadCode
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA
9040420900063D11C8EF10054038389C
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4C2BA6CCC1EF590459359F3CF0D2D676
9040420900063D11C8EF10054038389C
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\LCCWIZ.DLL
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\RICHED20.DLL
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\972C76EB8BAA3FC48B050BBD60F24C58
9040420900063D11C8EF10054038389C
01:\Software\Microsoft\Office\11.0\ResourceKit\CustomizableAlerts
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6985993B24351624FAB7F5D44C743291
9040420900063D11C8EF10054038389C
01:\Software\Microsoft\Office\11.0\ResourceKit\Localization
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\274B40034E1A6294197A7BA26A0E59B5
9040420900063D11C8EF10054038389C
01:\Software\Microsoft\Office\11.0\ResourceKit\OfficeInfo
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E12401EA121BD2344933A34BD88C91DC
9040420900063D11C8EF10054038389C
02:\Software\Microsoft\Office\11.0\ResourceKit\DocsRoot
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF37209E233E2054D8C03C046910C6EE
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Office Converter Pack\OCONVPCK.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A47C08BA20E46FB4B93FFC05406DFAE3
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Outlook Administrator Pack\ADMPACK.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\547BDF3B1D6C10D4EAF0AAB76DA84F79
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\ORK.CHM
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\33C89A717AE6A0B4F945BB1067215F7A
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Installation Wizard\CUSTWIZ.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B4AE02306336544CBBB4F7297DCAEE0
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Maintenance Wizard\MAINTWIZ.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2191CE1EAA23FF4E945F957E77B28EA
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\OFFICE11.OPA
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FACF64BD2454FA43966944821EB05EF
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\HTML Help Workshop\HTMLHELP.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE810C8159B07804BBC7CBB336B0BE6C
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\HTML Help Workshop\OFFICE11.CSS
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC0F72FB367749B4C894DA2426129A72
9040420900063D11C8EF10054038389C
01:\Software\Microsoft\Office\11.0\ResourceKit\PDFProPlus
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A07303437BEB604A9AC40C0E1216228
9040420900063D11C8EF10054038389C
C:\Windows\INF\INSTLR11.ADM
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2EC64E8EE5D218D49B37F6640D0BA2D2
9040420900063D11C8EF10054038389C
C:\Windows\INF\OFFICE11.ADM
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A38E807604CB4144CAFB26D63F3F18DC
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Profile Wizard\PROFLWIZ.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\638F6E6033757624D9571D658CA7E739
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\1033\OCLNINTL.OPC
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD913B4BBD66A0849A194F5C6CE9C5DF
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\OFFCLN.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1852A44288CCD684F8F11F9EFDDCE618
9040420900063D11C8EF10054038389C
02:\Software\Microsoft\Office\11.0\ResourceKit\ToolsRoot
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E01ED491B21D68478BF0D33F4D545BF
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\CMWVIEW.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B39E6E05274C0449B2346F0EC5D84AF
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\MSTVIEW.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D00F97475F4A3A948B3092B8483DD1A5
9040420900063D11C8EF10054038389C
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\OPSVIEW.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
9040420900063D11C8EF10054038389C
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Customizable Alerts\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\International Information\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Office Converter Pack\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Outlook Administrator Pack\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Installation Wizard\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Maintenance Wizard\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\HTML Help Workshop\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Package Definition Files\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Profile Wizard\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\1033\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
PatchGUID
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
MediaCabinet
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
File
OSE.EXE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
ComponentVersion
11.0.5525.0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
ProductVersion
11.0.5614
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
PatchSize
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
PatchAttributes
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
PatchSequence
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
SharedComponent
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2FFBA7ACD4FACF41929F6CCFE88DBDA\9040420900063D11C8EF10054038389C
IsFullFile
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{90240409-6000-11D3-8CFE-0150048383C9}\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCC347-0EDA-40D1-B30B-ECB5BD6C8E11}\InprocServer32
ThreadingModel
Apartment
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCC347-0EDA-40D1-B30B-ECB5BD6C8E11}\InprocServer32
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE11\1033\LCCWIZ.DLL
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCC347-0EDA-40D1-B30B-ECB5BD6C8E11}\DefaultIcon
C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE11\1033\LCCWIZ.DLL,0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCC347-0EDA-40D1-B30B-ECB5BD6C8E11}
Office Setup Files
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\11.0\ResourceKit
CustomizableAlerts
1
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\11.0\ResourceKit
Localization
1
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\11.0\ResourceKit
OfficeInfo
1
3728
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\11.0\ResourceKit
PDFProPlus
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Delivery\{90240409-6000-11D3-8CFE-0150048383C9}
CDCache
2
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Delivery\{90240409-6000-11D3-8CFE-0150048383C9}
DownloadCode
90240409-6000-11D3-8CFE-0150048383C9
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Delivery\{90240409-6000-11D3-8CFE-0150048383C9}
LocalCacheDrive
C
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\ResourceKit
DocsRoot
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\ResourceKit
ToolsRoot
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Office Setup Files
{7CBCC347-0EDA-40D1-B30B-ECB5BD6C8E11}
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90240409-6000-11D3-8CFE-0150048383C9}
SmartSourceDir
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
LocalPackage
C:\Windows\Installer\1092b0.msi
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
AuthorizedCDFPrefix
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Comments
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Contact
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
DisplayVersion
11.0.5614.0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
HelpLink
http://www.microsoft.com/support
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
HelpTelephone
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
InstallDate
20191009
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
InstallLocation
C:\Program Files\ORKTOOLS\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
InstallSource
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
ModifyPath
MsiExec.exe /I{90240409-6000-11D3-8CFE-0150048383C9}
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Publisher
Microsoft Corporation
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Readme
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Size
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
EstimatedSize
23682
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
UninstallString
MsiExec.exe /I{90240409-6000-11D3-8CFE-0150048383C9}
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
URLInfoAbout
http://www.microsoft.com/support
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
URLUpdateInfo
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
VersionMajor
11
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
VersionMinor
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
WindowsInstaller
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Version
184554990
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
Language
1033
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
AuthorizedCDFPrefix
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Comments
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Contact
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
DisplayVersion
11.0.5614.0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
HelpLink
http://www.microsoft.com/support
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
HelpTelephone
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
InstallDate
20191009
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
InstallLocation
C:\Program Files\ORKTOOLS\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
InstallSource
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
ModifyPath
MsiExec.exe /I{90240409-6000-11D3-8CFE-0150048383C9}
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Publisher
Microsoft Corporation
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Readme
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Size
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
EstimatedSize
23682
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
UninstallString
MsiExec.exe /I{90240409-6000-11D3-8CFE-0150048383C9}
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
URLInfoAbout
http://www.microsoft.com/support
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
URLUpdateInfo
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
VersionMajor
11
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
VersionMinor
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
WindowsInstaller
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Version
184554990
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
Language
1033
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\0000420000063D11C8EF00054038389C
9040420900063D11C8EF10054038389C
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\InstallProperties
DisplayName
Microsoft Office 2003 Resource Kit
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
DisplayName
Microsoft Office 2003 Resource Kit
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\71CE92CC2CB71D119A12000A9CE1A22A
1033\ork.chm
?ziCVn-}f(ZXfeAR6.jiOrkReadmeAndHelp>'[email protected]]GhOl39pX
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
DocsListsSamples
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
DocsListsSamples
Gw6y`lW8Z90$]wbf[-wjProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
OCP
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
OCP
)zWts+SB3=q$7n8qwK^uTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
CIW
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
CIW
^P$OHQ55'Ah=J][6]2.`SFL[*=Y%[email protected])DBW!NcJ}^r{6t,D)0dA+`BmM60M*aTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
CMW
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
CMW
^P$OHQ55'Ah=J][6]2.`r-S*4V,tz9h&Wp0iBTl'r{6t,D)0dA+`BmM60M*aTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
HTMLHelp
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
HTMLHelp
`-D~b=*b*@ElwSRHC]gz^!1z*7hng8X{w47I$7xhTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
PDF
DocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
PDF
wU2Mf4`[email protected]@CpUL9~=Qh0DocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
OPW
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
OPW
^P$OHQ55'Ah=J][6]2.`fel,I!Aus9e?A1K`R8'kTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
Tools
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
Tools
9HIa..Zb??^r%4tqhzZQProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
Viewers
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
Viewers
7~tpWL![??Z%X`4{q&kyCR=_'6Y~r9-OPy'f2RMyjF!MMZ,ha?CjdfTM*tzDTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
AlwaysInstalled
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
AlwaysInstalled
?ziCV6w&e=2Svg'RVds0?ziCV^!~N9du]@v`V)~nSp[t^jDq_A.bzdjbWIp`'OMdjoCKi8z8l}g57R8I
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
CARegistryFeature
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
CARegistryFeature
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
CustomizableAlerts
DocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
CustomizableAlerts
[email protected]@iT`[oR^E~RDocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
LocalizationDocs
DocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
LocalizationDocs
exMfbbmLD9U=[email protected])+DocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
NotInstalled
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
NotInstalled
ProductFiles
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
ORW
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
ORW
DdW6%]G)E9d(kuC!qGJW+aS)ch}(1?tAw]h9zWLzTools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
OfficeDocs
DocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
OfficeDocs
)jmL3t1JS?CD~f1K0$MEDocsListsSamples
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
OfficePolicyTemplates
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
OfficePolicyTemplates
.BgU9.dwd8HgDr&V,ToQEYFqs([email protected]_=V!vS2Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
OrkReadmeAndHelp
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
OrkReadmeAndHelp
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040420900063D11C8EF10054038389C
OutlookAdmPack
Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Features
OutlookAdmPack
g8?-`f,[email protected](id{AFUU08Tools
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040420900063D11C8EF10054038389C\Patches
AllPatches
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
ProductName
Microsoft Office 2003 Resource Kit
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
PackageCode
714A66F7AF30CAA4987E9100B25827DE
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
Language
1033
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
Version
184554990
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
Assignment
1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
AdvertiseFlags
388
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
ProductIcon
C:\Windows\Installer\{90240409-6000-11D3-8CFE-0150048383C9}\misc.exe,6
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
InstanceType
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
AuthorizedLUAApp
0
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
DeploymentFlags
3
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\0000420000063D11C8EF00054038389C
9040420900063D11C8EF10054038389C
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C\SourceList
PackageName
ORK.MSI
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C\SourceList\Net
1
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C\SourceList\Media
DiskPrompt
Microsoft Office 2003 Resource Kit
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C\SourceList\Media
1
OFFICE11;1
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C
Clients
:
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\9040420900063D11C8EF10054038389C\SourceList
LastUsedSource
n;1;C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
115
3728
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
3728
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72
3728
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3728
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3728
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
3728
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3728
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000422FD67FB57ED501C008000000070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000422FD67FB57ED501C0080000140C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
4000000000000000422FD67FB57ED501C0080000080A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
4000000000000000422FD67FB57ED501C0080000040A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000AAB8DF7FB57ED501C0080000040A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000AAB8DF7FB57ED501C0080000080A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
40000000000000005E7DE47FB57ED501C008000000070000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000B8DFE67FB57ED501C0080000140C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
4000000000000000A0E07E86B57ED501C0080000140C000001040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
4000000000000000FA428186B57ED501C0080000140C000001040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
400000000000000016918F86B57ED501C008000000070000E9030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
400000000000000016918F86B57ED501C0080000040A0000E9030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
400000000000000016918F86B57ED501C0080000140C0000E9030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
4000000000000000CA559486B57ED501C0080000040A0000E9030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000CA559486B57ED501C0080000040A000001000000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
4000000000000000CA559486B57ED501C0080000140C0000E9030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000CA559486B57ED501C0080000140C000001000000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
4000000000000000CA559486B57ED501C008000000070000E9030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000CA559486B57ED501C00800000007000001000000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
400000000000000002F2B086B57ED501C0080000040A0000F9030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
400000000000000002F2B086B57ED501C0080000140C0000F9030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
400000000000000002F2B086B57ED501C008000000070000F9030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
400000000000000002F2B086B57ED501C0080000040A0000F9030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
400000000000000002F2B086B57ED501C008000000070000F9030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
400000000000000002F2B086B57ED501C0080000140C0000F9030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000001019B886B57ED501C0080000700D000002040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000C09C3D87B57ED501C0080000700D000002040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
40000000000000001AFF3F87B57ED501C0080000700D0000EA030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
4000000000000000DCEA4B87B57ED501C0080000280B0000EA030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
4000000000000000DCEA4B87B57ED501C00800003C0D0000EA030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
4000000000000000DCEA4B87B57ED501C0080000F80C0000EA030000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
4000000000000000ACFD5E87B57ED501C0080000280B0000EA030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000ACFD5E87B57ED501C0080000280B000002000000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
400000000000000006606187B57ED501C0080000F80C0000EA030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000006606187B57ED501C0080000F80C000002000000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
400000000000000006606187B57ED501C00800003C0D0000EA030000000000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000006606187B57ED501C00800003C0D000002000000010000000100000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
400000000000000000E88987B57ED501C0080000700D0000EA030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
400000000000000000E88987B57ED501C0080000700D0000EB030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
400000000000000000E88987B57ED501C0080000700D0000EC030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
4000000000000000B4AC8E87B57ED501C00800003C0D0000EB030000010000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
4000000000000000B4AC8E87B57ED501C00800003C0D0000EB030000000000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000B4AC8E87B57ED501C00800003C0D000003000000010000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000B4AC8E87B57ED501C0080000A00F0000FC030000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
40000000000000000E0F9187B57ED501C0080000700D0000EC030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
40000000000000000E0F9187B57ED501C0080000700D0000ED030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
400000000000000068719387B57ED501C0080000700D0000ED030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
400000000000000068719387B57ED501C0080000700D0000EE030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
40000000000000001C369887B57ED501C00800004C0D0000EB030000010000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
40000000000000001C369887B57ED501C00800004C0D0000EB030000000000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000001C369887B57ED501C00800004C0D000003000000010000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000001C369887B57ED501C008000098080000FC030000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
40000000000000002A5D9F87B57ED501C0080000700D0000EE030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
40000000000000002A5D9F87B57ED501C0080000700D0000F0030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
40000000000000002A5D9F87B57ED501C0080000700D0000F0030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
400000000000000084BFA187B57ED501C0080000700D0000EF030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
4000000000000000DE21A487B57ED501C0080000F80C0000EB030000010000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
4000000000000000EC48AB87B57ED501C0080000F80C0000EB030000000000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000EC48AB87B57ED501C0080000F80C000003000000010000000200000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000EC48AB87B57ED501C008000058090000FC030000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
4000000000000000EC48AB87B57ED501C0080000700D0000EF030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
4000000000000000EC48AB87B57ED501C0080000700D0000EB030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
4000000000000000EC48AB87B57ED501C0080000700D000003040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
400000000000000046ABAD87B57ED501C0080000700D000003040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
400000000000000046ABAD87B57ED501C0080000700D0000FD030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
400000000000000046ABAD87B57ED501C0080000E40C0000FD030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
40000000000000000897B987B57ED501C0080000E40C0000FD030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
40000000000000000897B987B57ED501C0080000700D0000FD030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
40000000000000000897B987B57ED501C0080000E40C0000FE030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
400000000000000016BEC087B57ED501C0080000E40C0000FE030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
400000000000000016BEC087B57ED501C0080000E40C0000FF030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
400000000000000016BEC087B57ED501C0080000E40C0000FF030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
40000000000000000897B987B57ED501C0080000700D0000FE030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
400000000000000016BEC087B57ED501C0080000700D0000FE030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
400000000000000016BEC087B57ED501C0080000700D0000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
400000000000000016BEC087B57ED501C0080000700D0000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
400000000000000016BEC087B57ED501C0080000DC06000004040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
400000000000000016BEC087B57ED501C0080000DC06000004040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
400000000000000016BEC087B57ED501C0080000700D000005040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
40000000000000007020C387B57ED501C0080000700D000005040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
40000000000000007020C387B57ED501C0080000700D0000F4030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
40000000000000007020C387B57ED501C0080000700D0000F4030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
40000000000000007020C387B57ED501C0080000700D0000F2030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
40000000000000007E47CA87B57ED501C0080000280B0000F2030000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
40000000000000007E47CA87B57ED501C0080000FC0C0000F2030000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
40000000000000007E47CA87B57ED501C00800003C0D0000F2030000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000007E47CA87B57ED501C0080000A00F0000FC030000000000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000007E47CA87B57ED501C008000058090000FC030000000000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000007E47CA87B57ED501C008000098080000FC030000000000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
40000000000000007E47CA87B57ED501C0080000280B0000F2030000000000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
40000000000000007E47CA87B57ED501C0080000FC0C0000F2030000000000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
40000000000000007E47CA87B57ED501C00800003C0D0000F2030000000000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000007E47CA87B57ED501C0080000280B000004000000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000007E47CA87B57ED501C0080000FC0C000004000000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000007E47CA87B57ED501C00800003C0D000004000000010000000300000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
40000000000000007E47CA87B57ED501C0080000700D0000F2030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
40000000000000007E47CA87B57ED501C0080000700D000006040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
4000000000000000A2440888B57ED501C0080000700D000006040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
4000000000000000A2440888B57ED501C0080000700D0000F5030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
400000000000000072571B88B57ED501C0080000280B0000F5030000010000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
400000000000000072571B88B57ED501C0080000FC0C0000F5030000010000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
400000000000000072571B88B57ED501C0080000F80C0000F5030000010000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
400000000000000072571B88B57ED501C0080000F80C0000F5030000000000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
400000000000000072571B88B57ED501C0080000F80C000005000000010000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
400000000000000072571B88B57ED501C0080000FC0C0000F5030000000000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
400000000000000072571B88B57ED501C0080000FC0C000005000000010000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
4000000000000000689EC488B57ED501C0080000280B0000F5030000000000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000689EC488B57ED501C0080000280B000005000000010000000400000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
4000000000000000689EC488B57ED501C0080000700D0000F5030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
4000000000000000689EC488B57ED501C0080000700D000007040000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
4000000000000000704DF488B57ED501C0080000700D000007040000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
4000000000000000E6FD0489B57ED501C0080000700D0000FB030000010000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
4000000000000000F4240C89B57ED501C00800003C0D0000FB030000010000000500000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
4000000000000000F4240C89B57ED501C0080000F80C0000FB030000010000000500000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
4000000000000000F4240C89B57ED501C00800003C0D0000FB030000000000000500000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
4000000000000000F4240C89B57ED501C0080000FC0C0000FB030000010000000500000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
4000000000000000F4240C89B57ED501C0080000F80C0000FB030000000000000500000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
4000000000000000F4240C89B57ED501C0080000FC0C0000FB030000000000000500000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
2240
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
4000000000000000F4240C89B57ED501C0080000700D0000FB030000000000000000000000000000FF3571D6EA747D49AC041E603206DF670000000000000000
3416
DrvInst.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3312
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90240409-6000-11D3-8CFE-0150048383C9}
QuietUninstallString
MsiExec.Exe /x {90240409-6000-11D3-8CFE-0150048383C9} /qn
3312
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
66

Files activity

Executable files
26
Suspicious files
15
Text files
181
Unknown types
21

Dropped files

PID
Process
Filename
Type
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\ORK.MSI
executable
MD5: bdae5c55256bedc65aed3fdc17c506dc
SHA256: 946bead54a0b29933aa24856bdadc72595a7657aeba6f23f6ec68a5c98d71a7e
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\OFFCLN.EXE
executable
MD5: 8c1dbd8b245dafc7fe42981d4cc8e49b
SHA256: e377845e3f299a8ea57331ba933c13d4ac64869b3e734b67b5af0973f211399e
3728
msiexec.exe
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\LCCWIZ.DLL
executable
MD5: 6bc6e7b9d24184ed1eace4b319518468
SHA256: 9039a40a9b9a5510c67846b653f2ac4ec50ad97be14706560767e14463569fd0
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\MSTVIEW.EXE
executable
MD5: 28673be78402918a50ba97a31aee2b2d
SHA256: 5ba60c562229add05df9eaa21e04c972a3bb6dca45c1b9c1ab920a5fa61ea3b4
3728
msiexec.exe
C:\Windows\Installer\1092ad.msi
executable
MD5: bdae5c55256bedc65aed3fdc17c506dc
SHA256: 946bead54a0b29933aa24856bdadc72595a7657aeba6f23f6ec68a5c98d71a7e
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\RICHED20.DLL
executable
MD5: 8caf5c1748401032efabb3d52e27c1be
SHA256: c2c301d6674b08732538f25d870fc98cfaafe43dce3649f9fb31ad45a70554a2
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI2F54.tmp
executable
MD5: 38b4d2ede303e430848accc1d1845a00
SHA256: 264e404a0fb8a4c6742afc3759c2de854db2f0cc8dcb5d22b01ec105bd2e3149
3728
msiexec.exe
C:\Windows\Installer\$PatchCache$\Managed\9040420900063D11C8EF10054038389C\11.0.5614\OSE.EXE
executable
MD5: 7a56cf3e3f12e8af599963b16f50fb6a
SHA256: 882c82bae96d263138d4c0d6c425458b770b7b9c8e9c1d28ac918bf6be94a5c2
3452
OSE.EXE
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE
executable
MD5: 7a56cf3e3f12e8af599963b16f50fb6a
SHA256: 882c82bae96d263138d4c0d6c425458b770b7b9c8e9c1d28ac918bf6be94a5c2
3728
msiexec.exe
C:\Windows\Installer\{90240409-6000-11D3-8CFE-0150048383C9}\orkicons.exe
executable
MD5: f2aaf5613015216d289964f0c412fd36
SHA256: 128590e6338722c975545ff02f6e0c51cc39822436418156167902580e769812
3452
OSE.EXE
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\ORK.MSI
executable
MD5: bdae5c55256bedc65aed3fdc17c506dc
SHA256: 946bead54a0b29933aa24856bdadc72595a7657aeba6f23f6ec68a5c98d71a7e
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Office Converter Pack\OCONVPCK.EXE
executable
MD5: 480e7480984b12783bdea082ca3b7533
SHA256: 2776c6281e9e3d0d6e9751873a485a2b4808fda9ce6a07000f14544e9ab5f8da
3728
msiexec.exe
C:\Windows\Installer\{90240409-6000-11D3-8CFE-0150048383C9}\misc.exe
executable
MD5: 4616054b57ebdc3c885a67fa08f6967c
SHA256: 7510de051ee480d967b59b3d201ce2eb571af10bcd023f144d37f2442ed21f3d
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Outlook Administrator Pack\ADMPACK.EXE
executable
MD5: c0aefaa26d198e88284ba9b4191270d4
SHA256: 21fb5356b69f8bfa2d6a903dcfaba00da1a4adcca51719f61ca0ce57bf40cb48
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\SETUP.EXE
executable
MD5: d0d323b414b7748e713b51374d91b7d6
SHA256: 4248dc2814960c11e26a6c5c66868941d77a1651b028311ccb536b3dfe39baa0
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Installation Wizard\OCW_CPYF.DLL
executable
MD5: 0b763f7c6b84d916cd1a7f992a3f9c2d
SHA256: a1192044f0120ec0ea15f2ace7a24f7b99708b5fc64a5a3307f535af7a996e18
3728
msiexec.exe
C:\Windows\Installer\MSIA119.tmp
executable
MD5: fa353677c63b3570e311b5f589566d5e
SHA256: 6baeca33f686c872123e88d5464f506594ec4639e7d06beef7b3cabcf4ca9e5d
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Installation Wizard\CUSTWIZ.EXE
executable
MD5: b3bc9f973b450b3a099d194859e016d6
SHA256: 913cc147b6287d7d5b71681f50049946005967055e705873e78bc1430404045a
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\OSE.EXE
executable
MD5: 7a56cf3e3f12e8af599963b16f50fb6a
SHA256: 882c82bae96d263138d4c0d6c425458b770b7b9c8e9c1d28ac918bf6be94a5c2
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\CMWVIEW.EXE
executable
MD5: 1e4ccb74e41e16ceac44c4a0914ea4ef
SHA256: 81d8c5e38259b30272f7dd3aa777185d372c3e6abaf0c346b70cd00010852d0f
3728
msiexec.exe
C:\Windows\Installer\1092b0.msi
executable
MD5: bdae5c55256bedc65aed3fdc17c506dc
SHA256: 946bead54a0b29933aa24856bdadc72595a7657aeba6f23f6ec68a5c98d71a7e
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\HTML Help Workshop\HTMLHELP.EXE
executable
MD5: ffde6013c622c033d31fb892b283a1ce
SHA256: cf8fe5a02d3c2bf0c8728dd399dc3b2587c4139ffb23ef4268f34535a6157b87
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Maintenance Wizard\MAINTWIZ.EXE
executable
MD5: e1466cf6729cd8cd397ef946abfdd503
SHA256: 0c9199f4b46e00a258fbd66300ef7ad302e695ceb0c4319fc63e3b819f31dbc4
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Profile Wizard\PROFLWIZ.EXE
executable
MD5: fcbe69852d2d9aeb623c1a455d8ea67f
SHA256: 21a7400ba2295e7ce7ac7012700c606fcaa5192b72cbfe426f9cc726236800e2
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\OCLEAN.DLL
executable
MD5: 6a48e81f9a068c55d5ee2f7339371648
SHA256: 459a25b414e5492e86363cf78125d872e3f29db48411d93939a31aa78204bdb6
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\VIEWERS\OPSVIEW.EXE
executable
MD5: 74554b9028da791ae25efdfec1418b9b
SHA256: 38190662bf8554c50256845cc4725c34186404fa0609167faae80d6e161530ea
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Maintenance Wizard\MAINTWIZ.CHM
chm
MD5: 7e052fb4b29f393783bb1c2a999ba9d7
SHA256: 2d27ef64be92449608fc52a7e3d4ecebf927639ab998c936aacb967ea8bcb271
3728
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DFEB3B28036D536499.TMP
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\OCLNCUST.OPC
text
MD5: 14712ab9341aaa5ba811029f6498ee78
SHA256: 383022c5938e6e65ef60c7775948f8bf4e33e0ea17b1a6945c60a586b6f64f48
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\OCLNCORE.OPC
text
MD5: 014c89c4867d77691ba928ebb1c43897
SHA256: e09220f81c6e96c613ff68b72f82ddd08d03a503336f92f288919c46c7a84824
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Package Definition Files.lnk
lnk
MD5: 3fa59091d87fb5650ada73e47935b56a
SHA256: f72ec365dabab39f3f870e0270c5de7aabaeaeb61f5fde6d3b9cecef4a91ec70
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Profile Wizard\RESETO11.INI
text
MD5: 345bbee1523aa88d6e34fd8b6d0b4eb3
SHA256: 5a413e47822392d7c4414269c30370daf06af56d116f8ad235d14a5b3ae1f6fc
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Removal Wizard\1033\OCLNINTL.OPC
text
MD5: 03093e32ebf4b27d8c478df889b9cee8
SHA256: ea9d5877bde5e9905bca332c976435b4af1ef45dd20ad95d0b14b980a085da26
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Profile Wizard\PROFLWIZ.CHM
chi
MD5: 08fb71de63561e407c75dee25ab4fd40
SHA256: 668d2d68bca1ac78ef1f8f6ad5f57f498ae06d0643f169d919ce63f1d9b7fb77
3728
msiexec.exe
C:\Windows\INF\WORD11.ADM
text
MD5: 7b12512c27ccd855d56aa24a3931726c
SHA256: e62dd57e45baf4cb6ee9f8f80de41b4f8a1a04fed6a002ef3f177337f5a87238
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\International Information.lnk
lnk
MD5: 8b031acd265994ed5c6c1d6b570a6e56
SHA256: 4b2f2c2f88355a3ccfc73d6ce7e57c68645d93bc6702ea4f35bf5154c12e68b3
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Profile Wizard\OPW11ADM.INI
text
MD5: 768e787fde96f2b4b2bb31999ff71da1
SHA256: ddea668bd45d852170d99616330242cbd34e1f3150c9702256b1d47dbc795b5a
3728
msiexec.exe
C:\Windows\INF\PPT11.ADM
text
MD5: 6d444688a9db59cb9e85156b665785d8
SHA256: c3fef37ba4522361d9c12e267c77f641525ab2d6ec3f8243a5a11fbdd5fe90ad
3728
msiexec.exe
C:\Windows\INF\PUB11.ADM
text
MD5: f8f15dab9cd302b377214a490419067a
SHA256: 6e8e070c175075dd64e866a5f30073132bd532318688d1b4bb4ea3ac0a1eb1a7
3728
msiexec.exe
C:\Windows\INF\ONENT11.ADM
text
MD5: 003593077e6db149e4949262415bb006
SHA256: 884bce050c38a6e688ec3350ae9fecc5be83e76a574fb5e17663b952fa8316e5
3728
msiexec.exe
C:\Windows\INF\OUTLK11.ADM
text
MD5: c5de780ee8236831c2506875751b6add
SHA256: 2cee1668ecc0c934a41ef36c90ffefe53aed5d49cf876eeae629f0d9a9a9bccb
3728
msiexec.exe
C:\Windows\INF\OFFICE11.ADM
text
MD5: dc668be0881e4d5182c6fc210ed4437d
SHA256: 6696553f34dc442f04e9086b5098f628ad1ae3fda473d98900400e326738eea0
3728
msiexec.exe
C:\Windows\INF\GAL11.ADM
text
MD5: 78ed57616c5ddcdd9c03ab5393a7a8ad
SHA256: cbf27da5f8a0f621a75a55e33351d498e7bbf2cd570d0f6c0605a8579a176532
3728
msiexec.exe
C:\Windows\INF\INF11.ADM
text
MD5: 0379eea93852586ae5b691bad1f654a3
SHA256: 02d5e6ce47a21c17b16a4c24765c7f38bde516144338c1984cbe8aae8c2d270e
3728
msiexec.exe
C:\Windows\INF\FP11.ADM
text
MD5: 584c91171ba114e06892c65e079ef2ee
SHA256: cc020b7e1e98195382bf1900b893dde84fe369ba6987fd7aa445b21b000d6484
3728
msiexec.exe
C:\Windows\INF\EXCEL11.ADM
text
MD5: 8a64f23892cae11a08e79cab698c678b
SHA256: acf74f86eceffcdb6495e5cbe85d79ab1d9feae861ac7d05fc8263ce99629816
3728
msiexec.exe
C:\Windows\INF\INSTLR11.ADM
adm
MD5: 36610576a8b079a549812d1344c13a38
SHA256: 1395542475bcbbe4ea1fe68cf5278fe2774b1ffd48db3cc475cb28916ca6430f
3728
msiexec.exe
C:\Windows\INF\ACCESS11.ADM
text
MD5: d8394ef0f397c08bdc1ee06827b5480c
SHA256: 9d89b78e8c528e94c04c321bb141119922c1e5cd63585bde2c41a3dd129ac0a0
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Package Definition Files\MUI11.SMS
text
MD5: 7e75a4c19da1e267de55dbf3f9b3c39e
SHA256: 43f5e0bc1f313508c1e3975c59a197b667f78d06346a8bb12b0f4076a50e9dde
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Package Definition Files\OFFICE11.SMS
text
MD5: a08f23653f2371c128e49e4da0b09aac
SHA256: 7ce72616b730f5b6d3790944014a75471ddde2d21962959445b192edf80261a1
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Office Information.lnk
lnk
MD5: 6a744fc2f12408ac8a54d7c7656f18bf
SHA256: ef80c1054c0d24ca8edc3556ea79800bca428034c5bd41f9441f9db5b935715e
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\HTML Help Workshop\STARTPAG.CSS
text
MD5: 931df0f7217e249604f1f85f707e677d
SHA256: 00e10165d48f53484387f2b2cc9496988857bd223152ad4aa9fd6274d1c6c4c7
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\WORD11.OPA
text
MD5: 68487f1f9f5bc42a1b9024bb99c298f5
SHA256: 2211aaf61792834e8b9c2b8375e71eec543148330f07f4e845965454e9863b90
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\HTML Help Workshop\OFFICE11.CSS
text
MD5: fcad44ee88788e6a4c2df6fe32da1d8d
SHA256: 3b861891d834ab017b461b66b98c8216c47dd9c61b6cf6407fc2dce33929b149
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\PUB11.OPA
text
MD5: 8976db88bd0103aa7564def0a19cf7f7
SHA256: c5c17d6cb574d72ba6b62f463b528498de6c5a78f587b8b7c39fd21fb4edbacc
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\OUTLK11.OPA
text
MD5: 935e592ed30f838619b76fe83462f28b
SHA256: e3a1a961c5b1e68920304b77cfed2b6fe89b4f4df50b07cf778d31abc0edbfef
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\PPT11.OPA
text
MD5: 335f16f83c4929c8b207d31ec439d1c5
SHA256: 55bcba74166a232879506a6b9002c4493481cf987a8f735f37f882d63de625d1
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\ONENT11.OPA
text
MD5: a2ee4c6c6b2d47a434e6e79ffcf047d9
SHA256: a74f66ebb2651d277179f594c53aecf2810c375d6aa4fbc412979e296f70406e
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\OFFICE11.OPA
text
MD5: f5a4a6213647f48610a1f0e62107b6d7
SHA256: 68307e2ccf15c543fca5cfa43b284f32f6279e00033c0e1539269c81e7537dac
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\GAL11.OPA
text
MD5: 0c88cd28e7e4755a22bd2744636eab2b
SHA256: 1b40aa20cfebee90ba91afdd810fb4ed88043a850176ccfb285433666d0bc3ec
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\INF11.OPA
text
MD5: acdd33874628f9b8aec6b47ced919742
SHA256: 97b9498c68ee48e23f792781990b1e6bb0d8615e71f31bf44801bdf4ed474b2c
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\FP11.OPA
text
MD5: b821e60b769ac096bba9346cf405fccf
SHA256: 0ada6292b99fad996746413606215828a39b327fdd22a47c9852d87309921e5e
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Customizable Alerts.lnk
lnk
MD5: bb7cbb727527acb0df3db5046463aa7a
SHA256: 179d3636c2c2915646cc71ea40dcabc044909a0e2c5a4529040358bbbc21d443
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\ACCESS11.OPA
text
MD5: 8a075b678c9e155493a9a393d29c7fe1
SHA256: 32ded6bd70aff028d9d43e5f84c9ddda08eb2146ddf2e3324b0017e729581ffe
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\SHARED\EXCEL11.OPA
text
MD5: ec8ad26701248c7b9cb4e6eb2cadc277
SHA256: acf93bf94fb51e2a9f27e195b6e69e8c5cd93521c66664edab3108204b32cd05
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\ORK.CAB
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Removal Wizard.lnk
lnk
MD5: 5a0e6c45100ad0160514b5c6eb5064e3
SHA256: 22602b7ac45df3a0400a30bf0f0ffc94a8cfd4e35ed447bfdf981c6c9c8a147b
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Profile Wizard.lnk
lnk
MD5: 24309bbfed7c68e54b902f2be069c794
SHA256: c9ab27f5ccf20bf99292c60dd05bccf7db29fe5cf4c284072ebd60a9ecd08cad
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\ORK.CHM
chm
MD5: dd4f9bb9fda40abeb5ebc0f95ffb3593
SHA256: b1a8a2dd61e9554abcc337bad78ae75c50696ca453aefdc6ea1c10b3be712461
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\OPS File Viewer.lnk
lnk
MD5: f41ea7f4353e723b55bccdcc4fed0532
SHA256: f5375b7a0cd6766def8211980a888ff0d02b042734e002d52e08fb8d31c908e5
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\TOOLS\Custom Installation Wizard\CUSTWIZ.CHM
chm
MD5: 8ddc8f850bdc919b860834de15538597
SHA256: 66ff24005b1d0b36a1fe8be18902f8d495f4a8156a7f6e5e242bae5544c66a8b
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\MST File Viewer.lnk
lnk
MD5: 1e8fcc289971c0cfe8334752a77545d4
SHA256: b20b683c59dc5a13c437c9cbf137a86dc7439852d8116950d25e93f46cb1c0b5
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\STOPWORD.DOC
text
MD5: e492ea4dc607fad8d1f0231284f147a6
SHA256: 87447bf50350775c2efb35564515862ab229e85c69f12be91b7bdf8998608a6d
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\REGKEY.XLS
document
MD5: f1bc5a9220b8d550690b4055c433a0d9
SHA256: b6d8b08113816ffe6be2a980f94cedbcd687c48b3ff72d974d630e8e5b5e8791
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\PRESBROD.XLS
document
MD5: f47357d7c8a84539a8726c3672ced72c
SHA256: 6b5214145fdc89c0c5c3674cee0c88e469b33bdc8395326e015e5169372fd98d
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\MSCERT03.CER
der
MD5: 190224b743b60679fef69739f0c15d4a
SHA256: bea138041d6bac2fc00181804097ba9f1727eab6c6a4ec36ac80fc7120b63ccf
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\MSCERT01.CER
der
MD5: 67f0707d4111bd9941b29f539e9805e4
SHA256: b0741de955b1e02f81aaf2afec45992bc6c7e83a90e865b5f15b3475399c0da0
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\MSCERT02.CER
der
MD5: a234deb636d76b7eb0cf88a305b4acf3
SHA256: b3e602a514abbe0f0bcf71462631fe673df0958efef19b31cbaa4e92ddc02222
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\FILELIST.XLS
document
MD5: 2b59f4c9a7e75b99f81e3387f41b143c
SHA256: 4a9f7ae2a8697d2258d8616e824b27e673826e95a74c743a272685a6da64ad33
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Office Information\CFGQUIET.INI
text
MD5: 1be6aafddf76e9de162bfe4adacb8d30
SHA256: a26f7e71dbdd62b67e733546f228754e5cf56b3841651bab03c326d439f4aa55
2240
vssvc.exe
C:
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\International Information\WWSUPPT.XLS
document
MD5: c39d89e03c6d58a81ab6d327092782ab
SHA256: 55a29b28404f844fe738acb1c0dfc90fe31b93ff081a05b6464ce75e8c94e087
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\International Information\WWFEATRE.XLS
document
MD5: 86e393a40ac84141c00bf3ee179c83f6
SHA256: db885b5bf0135854301114440f7c9f88cc0add01221b211ff15f7c8f97be20e5
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\Customizable Alerts\ERRORMSG.XLS
document
MD5: 243aaf0560fa619e7c1fa5ba6f6bb9e5
SHA256: e070c79e1b1c07bb69e7006bcedb44c877b255b2480d506b8aef769690a7d164
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\International Information\MULTILPK.XLS
document
MD5: 5180474a4e8276f2520eea1dc4a91e4c
SHA256: acb77791d184384a54600836c9bf20beccbcd8b5c873fd331e5edf9b75232b89
3728
msiexec.exe
C:\Program Files\ORKTOOLS\ORK11\Lists and Samples\International Information\INTLIMIT.XLS
document
MD5: 92eaa1b82b02930b093083711d5d14b7
SHA256: f32b756ff05504fd0256ab199e62daabd2113e4ea0200af2bb4345bd9651dc97
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\CMW File Viewer.lnk
lnk
MD5: ca06f037c6a40260df42d4cbd25831d3
SHA256: f53f3cabcbb94fb0ee7bca82af5fecfadccb2f0b480459ad8d6d200b832e4eb8
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Custom Maintenance Wizard.lnk
lnk
MD5: dccde4afbff4efd13b4dddb55ce03260
SHA256: dc715a178d68afefd0ef7567870e45b6052fd5ff6ef14589869b50ef425c0d24
3728
msiexec.exe
C:\Windows\Installer\MSI99E4.tmp
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Windows\Installer\MSI9695.tmp
binary
MD5: cb74f192abb679010a79bee72c750fca
SHA256: c78e443b17e3451d95a7afb44a04574134889d3477e40ca3c395a016eeca5b84
3728
msiexec.exe
C:\Windows\Installer\MSI98C9.tmp
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Windows\Installer\MSI96A5.tmp
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Windows\Installer\1092ae.ipi
binary
MD5: 0a42fb6c982d258b4d635de883d8df46
SHA256: 43a7b2f5ce4b8b665fc25142e07cc4b54f61fbd39c77bdd93cbcbbfa7c2df55c
3728
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF60377E9D1D29C746.TMP
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Resource Kit\Custom Installation Wizard.lnk
lnk
MD5: 82778e904be1ea1ccdeb1f69832f478d
SHA256: 6d75e1c3474eab4d34a6b8ce6a5fa1efd94f8b8bf78ef54fb9ca77e988409ba6
3416
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
text
MD5: 617ec856e73dfeae687e38a8a9afd476
SHA256: 2d72e32720c7981f89c50faf90ee501e7ef1001f29988440c7598f4f2dae9512
3416
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 1c9563945651ae30ad67b6c80ae01483
SHA256: 513298ca77be9c0ff5a15045271795bb1201e5002ef46d3e95c12c37eb06e01e
3416
DrvInst.exe
C:\Windows\INF\setupapi.ev1
binary
MD5: 8f22e06957c13764da4aea417556fcce
SHA256: 360a52e68ec379f940630682661ab4f90a33921dab630237f59a0fb0d4b7af68
3416
DrvInst.exe
C:\Windows\INF\setupapi.ev3
binary
MD5: 8f761032829fb6121aee77e26dc667a6
SHA256: f83e1592023b7c8f6c15847f26d30770c0a52e6c7304dba951eea437e2737649
3728
msiexec.exe
C:\System Volume Information\SPP\metadata-2
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\System Volume Information\SPP\snapshot-2
binary
MD5: 96e92d39ca40a235c0d63272d463bed5
SHA256: 2ce80b420826c3c4ce8c4c196668c59fde1904fecb1dfeb664d86431b35f27fe
3728
msiexec.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{d67135ff-74ea-497d-ac04-1e603206df67}_OnDiskSnapshotProp
binary
MD5: 96e92d39ca40a235c0d63272d463bed5
SHA256: 2ce80b420826c3c4ce8c4c196668c59fde1904fecb1dfeb664d86431b35f27fe
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI5BE8.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI5BD8.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI55BC.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI55AC.tmp
––
MD5:  ––
SHA256:  ––
3452
OSE.EXE
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\ORK.CAB
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI4743.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI4732.tmp
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Windows\Installer\1092ae.ipi
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI2F43.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI2F33.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI2F22.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI2F02.tmp
––
MD5:  ––
SHA256:  ––
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSI2E94.tmp
––
MD5:  ––
SHA256:  ––
3076
SETUP.EXE
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt
text
MD5: ba3746b207ae0fce9d990ff4d60806ac
SHA256: 6df23b375c61fa399c029e1a66be77ba4c868c182de59e35b23a9ae69862a59c
3076
SETUP.EXE
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt
text
MD5: 3bc291e28a1d9d53e60cb852dd8970db
SHA256: a6df0aab7e1d6c0d511f91a9e014b82c4b1ab8e81a9269df8e7c6b3439db789e
3076
SETUP.EXE
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt
text
MD5: 1a0ed8fd4b53bc157d919cda487e30ac
SHA256: 147033db9ac7ded64d21b3ca9b83f40ef9972b8aac9af4ca662c9ebe9d55527e
3728
msiexec.exe
C:\Windows\Installer\MSIA38D.tmp
––
MD5:  ––
SHA256:  ––
3728
msiexec.exe
C:\Windows\Installer\MSIA35D.tmp
––
MD5:  ––
SHA256:  ––
3452
OSE.EXE
C:\MSOCache\All Users\90240409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\ORKTOOLS\ORK11\ORK.CHM
chm
MD5: dd4f9bb9fda40abeb5ebc0f95ffb3593
SHA256: b1a8a2dd61e9554abcc337bad78ae75c50696ca453aefdc6ea1c10b3be712461
3076
SETUP.EXE
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt
text
MD5: 2a41e29d9bab645f9b9b0179fbe39b35
SHA256: 373b3deb0dd3532f120e49f302cdd2e295a35fa906e2adcefcc0b6ff3f4f4ff7
3076
SETUP.EXE
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt
text
MD5: c2f684244e6108d5500bae013697792d
SHA256: b77b33d1964bd6532dac5aa74c49952a7eb6863c5e2be690349fb538654334e4
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\ork.xml
xml
MD5: f2946a842ca35ad62c06144090435921
SHA256: a51e4a88f632af8494495dd5575dde794523984714ff99ceb679d807418feda4
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\SETUP.INI
text
MD5: c2d3b071382b578318f4593cb9f516fe
SHA256: 07b8f3f300f49e279a7e2ea78ba90c8fc077b66ff273b33c6818767ae8cf1d98
3728
msiexec.exe
C:\Config.Msi\1092af.rbs
binary
MD5: a52d72547bd6912d54f5b121fdcf5c6f
SHA256: 5a7f148b071b19f32287c0b513671749951020de85f0c44ce74e26499f1e1276
3940
Office Converter Pack.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\ORK.CHM_1033
chm
MD5: dd4f9bb9fda40abeb5ebc0f95ffb3593
SHA256: b1a8a2dd61e9554abcc337bad78ae75c50696ca453aefdc6ea1c10b3be712461
3728
msiexec.exe
C:\Windows\Installer\MSIA1D6.tmp
––
MD5:  ––
SHA256:  ––
3076
SETUP.EXE
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001).txt
text
MD5: 2724fb5ee06a1670edc297f4d6fe963f
SHA256: d4dbd91377732af75e5a718f1c865005347fa78ff950a177f30efe45b165a565
2720
msiexec.exe
C:\Users\admin\AppData\Local\Temp\Microsoft Office 2003 Resource Kit Setup(0001)_Task(0001).txt
text
MD5: ca92be6b4302e68d5e1b619ad98229a3
SHA256: c29d7b25c7fba1c8a087c1a952a168b9853934777dedfa8cd0755e0e92310717

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.