General Info

File name

SlimCleanerPlus.exe

Full analysis
https://app.any.run/tasks/59aad33d-002e-487f-9078-763a2efdd93e
Verdict
Malicious activity
Analysis date
10/9/2019, 18:07:55
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

69484c39e6aa358b57617b6e6e300d5a

SHA1

f9665fae82d5f02250b25825e36de974593623f3

SHA256

7177c05a6f7a7759098d5f94b67a8a5c168a4718f5ac04bd4743bf34d1af8945

SSDEEP

3072:D06uN3fztYXIUlQI1p0hDKt3b+zd7uBD/vQiwmJjs7UurJJhK6bJtld82:3e3fzZYWorJYMj2UgXhK6bxS2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Downloads executable files from the Internet
  • SlimCleanerPlus.exe (PID: 3572)
Application was dropped or rewritten from another process
  • DriverUpdate-setup.exe (PID: 3552)
Creates COM task schedule object
  • msiexec.exe (PID: 2160)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 2160)
  • SlimCleanerPlus.exe (PID: 3572)
Changes IE settings (feature browser emulation)
  • MsiExec.exe (PID: 3124)
Creates a software uninstall entry
  • msiexec.exe (PID: 2160)
Dropped object may contain Bitcoin addresses
  • msiexec.exe (PID: 2160)
Creates files in the program directory
  • msiexec.exe (PID: 2160)
Application launched itself
  • msiexec.exe (PID: 2160)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:02:01 19:37:13+01:00
PEType:
PE32
LinkerVersion:
12
CodeSize:
144896
InitializedDataSize:
107520
UninitializedDataSize:
null
EntryPoint:
0x14b8b
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
2.4.1.0
ProductVersionNumber:
2.4.1.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
CompanyName:
SlimWare Utilities Holdings, Inc.
FileDescription:
DriverUpdate SlimWare Downloader
FileVersion:
2.4.1
InternalName:
SlimWare Downloader
LegalCopyright:
Copyright 2014-2017 SlimWare Utilities Holdings, Inc.
OriginalFileName:
SlimWareDownloader.exe
ProductName:
DriverUpdate
ProductVersion:
2.4.1
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
01-Feb-2019 18:37:13
Detected languages
English - United States
Debug artifacts
E:\BuildAgent\work\3a43d99f69f7172d\bin\Release\DriverUpdate-Downloader.pdb
CompanyName:
SlimWare Utilities Holdings, Inc.
FileDescription:
DriverUpdate SlimWare Downloader
FileVersion:
2.4.1
InternalName:
SlimWare Downloader
LegalCopyright:
Copyright 2014-2017 SlimWare Utilities Holdings, Inc.
OriginalFilename:
SlimWareDownloader.exe
ProductName:
DriverUpdate
ProductVersion:
2.4.1
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
01-Feb-2019 18:37:13
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000235AD 0x00023600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.59193
.rdata 0x00025000 0x0000C806 0x0000CA00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.45068
.data 0x00032000 0x000052E8 0x00001E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.19659
.rsrc 0x00038000 0x00005950 0x00005A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.65242
.reloc 0x0003E000 0x00002A6C 0x00002C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.56255
Resources
1

2

3

4

Imports
    KERNEL32.dll

    USER32.dll

    ole32.dll

    CRYPT32.dll

    WINTRUST.dll

    SHELL32.dll (delay-loaded)

Exports

    No exports.

Screenshots

Processes

Total processes
40
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

+
download and start start slimcleanerplus.exe no specs slimcleanerplus.exe driverupdate-setup.exe no specs msiexec.exe msiexec.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2916
CMD
"C:\Users\admin\AppData\Local\Temp\SlimCleanerPlus.exe"
Path
C:\Users\admin\AppData\Local\Temp\SlimCleanerPlus.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
SlimWare Utilities Holdings, Inc.
Description
DriverUpdate SlimWare Downloader
Version
2.4.1
Modules
Image
c:\users\admin\appdata\local\temp\slimcleanerplus.exe
c:\systemroot\system32\ntdll.dll

PID
3572
CMD
"C:\Users\admin\AppData\Local\Temp\SlimCleanerPlus.exe"
Path
C:\Users\admin\AppData\Local\Temp\SlimCleanerPlus.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
SlimWare Utilities Holdings, Inc.
Description
DriverUpdate SlimWare Downloader
Version
2.4.1
Modules
Image
c:\users\admin\appdata\local\temp\slimcleanerplus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\driverupdate-setup.exe

PID
3552
CMD
"C:\Users\admin\AppData\Local\Temp\DriverUpdate-setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\DriverUpdate-setup.exe
Indicators
No indicators
Parent process
SlimCleanerPlus.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
SlimWare Utilities, Inc.
Description
SlimWare Installer
Version
2.3.1
Modules
Image
c:\users\admin\appdata\local\temp\driverupdate-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll

PID
2160
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\propsys.dll

PID
3124
CMD
C:\Windows\system32\MsiExec.exe -Embedding 385CDC995217F3A447D9D01CE9D9B276
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi6cc1.tmp
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\psapi.dll
c:\windows\installer\msi6e59.tmp

Registry activity

Total events
437
Read events
203
Write events
227
Delete events
7

Modification events

PID
Process
Operation
Key
Name
Value
3572
SlimCleanerPlus.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc
MachineID
9A0B12CEA4F7D74A82E20523B06839AB
3572
SlimCleanerPlus.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3572
SlimCleanerPlus.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc\DriverUpdate\InstallerData
ul_stubid
097705DC-A0B0-4775-BFB5-DDDCF14B8204
3572
SlimCleanerPlus.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc\DriverUpdate\Registration
InstallationID
0A04D6BF09511F44A081A27BB3837720
3552
DriverUpdate-setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
65
2160
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2160
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
70080000F6F872C3BB7ED501
2160
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
90C4AC7B9A2B88BCD14BC01777E68270F01B2C98673A9B9BA48544D8A018A582
2160
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\116afe.ipi
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\116aff.rbs
30768836
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\116aff.rbsLow
638132544
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\513C2FCB818471C569E0FDA5A3BDE0E0
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\DriverUpdate.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42194C3DC88215C57AF047A1468C0C52
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\SlimWare.DriverUpdate.Services.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA31A15E960112C508A2BF280A5AF15D
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\SlimWare.Messaging.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8730FAEEF4356AE57901B5464C4B3A3C
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\SlimWare.PushNotification.Services.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9182F476578643550AFFF32CC6EC70A7
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\UninstallStub.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3F442702345E725FBFEC4A9FABA5BC3
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\Open-Source Licenses.txt
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34F23E3E5392468529F04A9FA6314512
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\lib-inappbrowser.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\40D6AC1309CE4565587E09CF3AF5A0FA
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\InAppBrowserProxy.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\66D733525E9A58F57966D7601ED64574
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\UnifiedLogger.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\698C8E94F9E19FD52A448DEDF67C8BFB
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\BsSndRpt.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\601E9206EEC8D2E5ABE66F2499D4B1D7
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\BugSplat.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3584B01D823AA13508B011BBA6BD624A
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\BugSplatRc.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5495805C52029135CA3898C4D31E1381
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\dbghelp-app.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE2B95E5EA141C156BBDC4F095406FD6
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\DriverUpdate\htmlayout.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26DA28C9A03553C5488D3F67405E5D27
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\SlimWare.Core.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F80D48B9C03F1F754A5B3FEE9E4E7D7C
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D713F65C8E5D565F86371B866E46828
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.ProxyStub.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CAB465E9D3FE71F529A5972E38168E5D
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A0820E9C0833935BBEF4392EEF6FBFD
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.ProxyStub.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D3E0B51CDEA04D5090F226906305310
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\BsSndRpt.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BDAC067F835493755BABA7F70CAE4D25
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\DriverUpdate.UpdateLauncher.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E810A09F736895651868E8951B49FA83
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\BugSplat.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64924E41CD2B1715DB61B077B3641BE7
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\BugSplatRC.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B490B324AF2CBCB5CBD122FDB87D01B4
A0DF1B1BA2FF75140A68AC9C088EBAA0
C:\Program Files\SlimWare Utilities\Services\dbghelp.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\SlimWare Utilities\Services\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\SlimWare Utilities\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\DriverUpdate\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}
ISlimWareSession
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\TypeLib
{58A8BF1A-3608-41EA-AAD1-581AB79105E6}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\TypeLib
Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\BaseInterface
{00020400-0000-0000-C000-000000000046}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\NumMethods
11
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\ProxyStubClsid32
{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8}\LocalServer32
"C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.exe"
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8}\LocalServer32
ThreadingModel
Free
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8}
AppID
{F6A8CE42-CB2D-4920-85E7-24966D63D4B9}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8}
SlimWare Services Session
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8}\TypeLib
{58A8BF1A-3608-41EA-AAD1-581AB79105E6}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8}\Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F6A8CE42-CB2D-4920-85E7-24966D63D4B9}
SlimWare.Services
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F6A8CE42-CB2D-4920-85E7-24966D63D4B9}
LocalService
SlimWareServices
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}\1.0
SlimWareServices
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}\1.0\0\win32
C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}\1.0\FLAGS
0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\InprocServer32
C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.ProxyStub.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\InprocServer32
ThreadingModel
Both
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}
PSFactoryBuffer
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3B8B86CB-0248-4F00-AC0E-EE5C6795D7F4}
ISlimWareSessionServer
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3B8B86CB-0248-4F00-AC0E-EE5C6795D7F4}\TypeLib
{CE74B1E6-4EBC-42A1-A4EF-E03F45195608}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3B8B86CB-0248-4F00-AC0E-EE5C6795D7F4}\TypeLib
Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3B8B86CB-0248-4F00-AC0E-EE5C6795D7F4}\BaseInterface
{6D5140C1-7436-11CE-8034-00AA006009FA}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3B8B86CB-0248-4F00-AC0E-EE5C6795D7F4}\NumMethods
7
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3B8B86CB-0248-4F00-AC0E-EE5C6795D7F4}\ProxyStubClsid32
{BDF76960-B341-4592-BDBA-DFC8C74165A9}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDF76960-B341-4592-BDBA-DFC8C74165A9}
ISlimWareSessionServerFactory
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\TypeLib
{CE74B1E6-4EBC-42A1-A4EF-E03F45195608}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\TypeLib
Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\BaseInterface
{00000000-0000-0000-C000-000000000046}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\NumMethods
4
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\ProxyStubClsid32
{BDF76960-B341-4592-BDBA-DFC8C74165A9}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B}\LocalServer32
"C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.exe"
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B}\LocalServer32
ThreadingModel
Free
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B}
AppID
{6D3BC646-CFCD-4098-8495-B7BD0DF13133}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B}
SlimWare Services Session Server
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B}\TypeLib
{CE74B1E6-4EBC-42A1-A4EF-E03F45195608}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B}\Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{6D3BC646-CFCD-4098-8495-B7BD0DF13133}
SlimWare.Session
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE74B1E6-4EBC-42A1-A4EF-E03F45195608}\1.0
SlimWareSession
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE74B1E6-4EBC-42A1-A4EF-E03F45195608}\1.0\0\win32
C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE74B1E6-4EBC-42A1-A4EF-E03F45195608}\1.0\FLAGS
0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\InprocServer32
C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.ProxyStub.dll
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\InprocServer32
ThreadingModel
Both
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF76960-B341-4592-BDBA-DFC8C74165A9}
PSFactoryBuffer
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AEC63C2-831A-4134-8EB0-02C0B7B97620}
IJobLauncher
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AEC63C2-831A-4134-8EB0-02C0B7B97620}\TypeLib
{31E87E80-E113-49FD-9789-A97E83CEA4F1}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AEC63C2-831A-4134-8EB0-02C0B7B97620}\TypeLib
Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AEC63C2-831A-4134-8EB0-02C0B7B97620}\NumMethods
9
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AEC63C2-831A-4134-8EB0-02C0B7B97620}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9276E23-AD64-404D-8D3C-1EBB1F965E40}
DJobLauncherEvents
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9276E23-AD64-404D-8D3C-1EBB1F965E40}\TypeLib
{31E87E80-E113-49FD-9789-A97E83CEA4F1}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9276E23-AD64-404D-8D3C-1EBB1F965E40}\TypeLib
Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9276E23-AD64-404D-8D3C-1EBB1F965E40}\NumMethods
8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9276E23-AD64-404D-8D3C-1EBB1F965E40}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}\LocalServer32
"C:\Program Files\SlimWare Utilities\Services\DriverUpdate.UpdateLauncher.exe"
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}\LocalServer32
ThreadingModel
Free
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}
AppID
{BAF61B64-5D1A-4108-97CB-A10B7DDF730E}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}
Update Launcher Server
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}
LocalizedString
@C:\Program Files\SlimWare Utilities\Services\DriverUpdate.UpdateLauncher.exe,-100
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}\TypeLib
{31E87E80-E113-49FD-9789-A97E83CEA4F1}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}\Version
1.0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BAF61B64-5D1A-4108-97CB-A10B7DDF730E}
DriverUpdate.UpdateLauncher
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{31E87E80-E113-49FD-9789-A97E83CEA4F1}\1.0
DriverUpdate.UpdateLauncher
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{31E87E80-E113-49FD-9789-A97E83CEA4F1}\1.0\0\win32
C:\Program Files\SlimWare Utilities\Services\DriverUpdate.UpdateLauncher.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{31E87E80-E113-49FD-9789-A97E83CEA4F1}\1.0\FLAGS
0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5139FDE1-9FDE-4D4C-89D0-5D016161B13A}\Elevation
Enabled
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc\DriverUpdate\Registration
dmm
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc\DriverUpdate\Registration
lv
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
Comments
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
Contact
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
DisplayIcon
"C:\Program Files\DriverUpdate\DriverUpdate.exe",0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
DisplayName
DriverUpdate
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
DisplayVersion
5.8.8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
HelpLink
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
HelpTelephone
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
InstallLocation
C:\Program Files\DriverUpdate\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
InstallSource
C:\Program Files\Downloaded Installers\{b1b1fd0a-ff2a-4157-a086-cac980e8ab0a}\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
UninstallString
"C:\Program Files\DriverUpdate\UninstallStub.exe" {b1b1fd0a-ff2a-4157-a086-cac980e8ab0a}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
Publisher
Slimware Utilities Holdings, Inc.
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
Readme
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
Size
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
URLInfoAbout
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
URLUpdateInfo
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
NoModify
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
NoRepair
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
VersionMajor
5
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate
VersionMinor
8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
LocalPackage
C:\Windows\Installer\116b00.msi
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
AuthorizedCDFPrefix
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Comments
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Contact
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
DisplayVersion
5.8.8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
HelpLink
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
HelpTelephone
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
InstallDate
20191009
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
InstallLocation
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
InstallSource
C:\Users\admin\AppData\Local\Downloaded Installers\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
ModifyPath
MsiExec.exe /X{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
NoModify
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Publisher
Slimware Utilities Holdings, Inc.
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Readme
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Size
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
EstimatedSize
49086
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
SystemComponent
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
UninstallString
MsiExec.exe /X{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
URLInfoAbout
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
URLUpdateInfo
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
VersionMajor
5
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
VersionMinor
8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
WindowsInstaller
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Version
84410376
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
Language
1033
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
AuthorizedCDFPrefix
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Comments
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Contact
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
DisplayVersion
5.8.8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
HelpLink
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
HelpTelephone
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
InstallDate
20191009
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
InstallLocation
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
InstallSource
C:\Users\admin\AppData\Local\Downloaded Installers\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
ModifyPath
MsiExec.exe /X{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
NoModify
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Publisher
Slimware Utilities Holdings, Inc.
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Readme
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Size
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
EstimatedSize
49086
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
SystemComponent
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
UninstallString
MsiExec.exe /X{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
URLInfoAbout
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
URLUpdateInfo
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
VersionMajor
5
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
VersionMinor
8
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
WindowsInstaller
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Version
84410376
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
Language
1033
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
A0DF1B1BA2FF75140A68AC9C088EBAA0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\InstallProperties
DisplayName
DriverUpdate
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}
DisplayName
DriverUpdate
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\A0DF1B1BA2FF75140A68AC9C088EBAA0
Application
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\Features
Application
[zqfeQxnZE]oR5EZ8'T'wG=(m1w~aEnSbR+7[G.07nm^ruar[EQ&=+Rd_ARmBgXeu{`fKF6^[9H_[`[email protected])dLg6hg6O2+,A%%Z^SBj4CZYv8TS7cl^[email protected]!4PMQhCy+o2z6`v9ae{@z.GRWdFT,A*%iF`w=e9-i?9W85Fr8s]p(D^]fD'*vF*0p=F1CET9Rvj5PKRq3lbKBeB&MN-e5qMi]?]eCh*e0eB)[email protected]~{j*![VCF&XN?Blh}v'?,$EKWscAZmM%_EEG`7NZ=3vLS1[}YrsW=DfquluAKR7ia0GyCr&IiC7AmdT7&lyQkSZtZw2qWFrf$lqwMfhmDN`[email protected]'g81},VvpVhX{)QYW{EcoW9Xm{{H!~1+Sx2eq%D9eZ{PP!s]Bg1P&[email protected]}hCn8ZkDVYZ667efe){vz2B$5.=N*[email protected][email protected]
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\Patches
AllPatches
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
ProductName
DriverUpdate
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
PackageCode
11F26AACE51368B4EA39425246088E81
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
Language
1033
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
Version
84410376
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
Assignment
1
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
AdvertiseFlags
388
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
ProductIcon
C:\Windows\Installer\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\Icon.exe
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
InstanceType
0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
AuthorizedLUAApp
0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
DeploymentFlags
3
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
A0DF1B1BA2FF75140A68AC9C088EBAA0
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\SourceList
PackageName
setup.msi
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\SourceList\Net
1
C:\Users\admin\AppData\Local\Downloaded Installers\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\SourceList\Media
1
;
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0
Clients
:
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A0DF1B1BA2FF75140A68AC9C088EBAA0\SourceList
LastUsedSource
n;1;C:\Users\admin\AppData\Local\Downloaded Installers\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\
2160
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
115
2160
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
2160
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72
2160
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
2160
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
2160
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
2160
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3124
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
340C0000686804C4BB7ED501
3124
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
850ED5737F7D3F03B3557EE61FB2C45A63D71324C3BF5E492B83CA58628E5635
3124
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
3124
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\Program Files\DriverUpdate\DriverUpdate.exe
3124
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
22D86E1E9ABBAE631DAE15E385E5FA8C1552D9BFAD9EFCE47E379FF6538B6C18
3124
MsiExec.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
3124
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc\DriverUpdate\Registration
InstallationID
00BE71793698B643B35AD646E0031296
3124
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
DriverUpdate.exe
11001

Files activity

Executable files
28
Suspicious files
3
Text files
1
Unknown types
3

Dropped files

PID
Process
Filename
Type
2160
msiexec.exe
C:\Program Files\DriverUpdate\lib-inappbrowser.dll
executable
MD5: 56f52bbbc95479faf6cc62bf470a609c
SHA256: 53d1198d7cec7e9a09c01fd2fe003208d98d86affd22f951207d3ec71367a991
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.ProxyStub.dll
executable
MD5: c211693c9790089508fb1b1d4d6acb21
SHA256: 856fe1013c7f82db38d98c1b1dad1e5dddd9874c8185829d0bf58425c0e1661b
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\dbghelp.dll
executable
MD5: dee832103585ee41bd7f1a905f0726f7
SHA256: 3ab019bd41c6f30d4250f26b40e695021698d7909d538e2f9b8aeab73bb7b8aa
2160
msiexec.exe
C:\Program Files\DriverUpdate\UninstallStub.exe
executable
MD5: 69599090d9a157c41582fd57259b5fa9
SHA256: 49bea0579436de43ae0907565be024f266b67718d65db17addc599a66dffcc47
2160
msiexec.exe
C:\Program Files\DriverUpdate\dbghelp-app.dll
executable
MD5: dee832103585ee41bd7f1a905f0726f7
SHA256: 3ab019bd41c6f30d4250f26b40e695021698d7909d538e2f9b8aeab73bb7b8aa
2160
msiexec.exe
C:\Program Files\DriverUpdate\UnifiedLogger.dll
executable
MD5: b4360e08d963788265d2708a629b2f15
SHA256: dfd28d380dc7776fe676267d0012d0ac90ec8ce8251ff386148b5b7ae4bb8429
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\BugSplat.dll
executable
MD5: e294d13f8b64989a2b15b558f567d7ba
SHA256: 6fd184e4e2b1d4ca2314f4d16b0e86a0e398054038a2235086d588f02bf39c67
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\BsSndRpt64.exe
executable
MD5: 2dd28460d99233d7b1fe71c16f11fed0
SHA256: bc5164470e16524393a53930cf362119b1596dea7b9f521507f9ef792de2b9f0
2160
msiexec.exe
C:\Program Files\DriverUpdate\BsSndRpt.exe
executable
MD5: 2dd28460d99233d7b1fe71c16f11fed0
SHA256: bc5164470e16524393a53930cf362119b1596dea7b9f521507f9ef792de2b9f0
2160
msiexec.exe
C:\Program Files\DriverUpdate\dbghelp.dll
executable
MD5: dee832103585ee41bd7f1a905f0726f7
SHA256: 3ab019bd41c6f30d4250f26b40e695021698d7909d538e2f9b8aeab73bb7b8aa
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\DriverUpdate.UpdateLauncher.exe
executable
MD5: de8ea26a774084ab65e65de2494ea39b
SHA256: 2dffe6b8eb6905f778829623a344803a8adfebeb357b57c11683ba28313eeb2e
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\BugSplatRC.dll
executable
MD5: 5eea312e33708456f292bf602a40bb85
SHA256: 165ec5e4c9f3fa640d155978427988af4563587489d0e31643e38b6e8e4c092d
2160
msiexec.exe
C:\Program Files\DriverUpdate\htmlayout.dll
executable
MD5: ee2540c23fc04dd39a17cc466ff3c946
SHA256: 5c43198ee7e9e4c94f4700a8032d368d3854c6b7e2f04a930d23b373f55ee003
2160
msiexec.exe
C:\Windows\Installer\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\Icon.exe
executable
MD5: b99a4a60a521b10ba8de04f9bf3ee491
SHA256: ac5cb00db32067b753c16441f0fd8007ff470309ba880727eee65a5d0482a90d
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\SlimWare.Core.dll
executable
MD5: 79722b11d101a8222b08e1c6331bca14
SHA256: b6725c94a862e4ce990ab1037ccb931cfed97f66810177061dc7e154fd37b5b5
2160
msiexec.exe
C:\Program Files\DriverUpdate\BugSplat.dll
executable
MD5: e294d13f8b64989a2b15b558f567d7ba
SHA256: 6fd184e4e2b1d4ca2314f4d16b0e86a0e398054038a2235086d588f02bf39c67
2160
msiexec.exe
C:\Program Files\DriverUpdate\SlimWare.DriverUpdate.Services.dll
executable
MD5: e561c4316bb8114541344169a45fcc8c
SHA256: ee21320fb14fe1cf22a5c899900cf54f0c2edb638bc49697e4d2c2a8fa046d1d
2160
msiexec.exe
C:\Program Files\DriverUpdate\SlimWare.Messaging.dll
executable
MD5: 3cffb51bff5253750883d550058563d5
SHA256: 74eed03e8765930530bd1a44513434fc5e7155877411c9e3357169a550d22137
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.ProxyStub.dll
executable
MD5: 2edc6a867218c146c6c8a41cd2f98820
SHA256: 653484b25345511d7b1fc176360835d947736adb95096701f250fbf8e7c5dfb7
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\BsSndRpt.exe
executable
MD5: 2dd28460d99233d7b1fe71c16f11fed0
SHA256: bc5164470e16524393a53930cf362119b1596dea7b9f521507f9ef792de2b9f0
2160
msiexec.exe
C:\Program Files\DriverUpdate\SlimWare.PushNotification.Services.dll
executable
MD5: 82730d71ad777e87ffbb4903727d0f8c
SHA256: 5ceaa6bbf3f7c1e34f00c4e4d434ae6aa50625d4ad303a18ef2b4ce8058b47dc
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\BugSplatRC64.dll
executable
MD5: 5eea312e33708456f292bf602a40bb85
SHA256: 165ec5e4c9f3fa640d155978427988af4563587489d0e31643e38b6e8e4c092d
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.exe
executable
MD5: bef32279b87f68bab434352d3fe59ba8
SHA256: 5b978e5ac841c63079f60a3bf36e2e4c2c50887823a050b54ad0e6536c6759eb
3572
SlimCleanerPlus.exe
C:\Users\admin\AppData\Local\Temp\DriverUpdate-setup.exe
executable
MD5: ac4cd5856bfd9708c3eb99394be78b1b
SHA256: dd2285c8df55cee7f813d8f7f324cc4df71f8a097337be93c35988be102d511a
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.exe
executable
MD5: ae63d0e42deb08fc7ea20d4c313ce864
SHA256: 33fce7ac1c16cf5b080eda09c9ab9c21f2975d5adcc9c012c7b806170d4df62f
2160
msiexec.exe
C:\Program Files\DriverUpdate\InAppBrowserProxy.dll
executable
MD5: 0f58ff3b50079347f858caef1c307f50
SHA256: 005e09fadee68efc1457eeb5f83f2d8f907946239327a4b61be65c694cedf437
2160
msiexec.exe
C:\Program Files\DriverUpdate\BugSplatRc.dll
executable
MD5: 81e1bfd6dca11ce24872896a18eecf25
SHA256: 8e123d21e0b96563f51acc5f50a2b120f9a6c077213881b24a9a304b46f4e7c8
2160
msiexec.exe
C:\Program Files\SlimWare Utilities\Services\BugSplat64.dll
executable
MD5: e294d13f8b64989a2b15b558f567d7ba
SHA256: 6fd184e4e2b1d4ca2314f4d16b0e86a0e398054038a2235086d588f02bf39c67
2160
msiexec.exe
C:\Windows\Installer\MSI6E59.tmp
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Windows\Installer\116afe.ipi
binary
MD5: aaa5f88a0caebf29d9efdac45bb0846c
SHA256: 0d7bc87caad6ff44bd843f2076c16e24affe01ac8ef52247feda5dc5f0a61513
2160
msiexec.exe
C:\Windows\Installer\116b00.msi
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Users\Public\Desktop\DriverUpdate.lnk
lnk
MD5: e39db2511c1d3554c58b7acae37ed3e6
SHA256: 265705e538c075c5debebd196c6ce0f4527d2f1b151a4d0ea3d8c1a8885c08fd
2160
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DFE294E3E86E56866B.TMP
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Program Files\DriverUpdate\Open-Source Licenses.txt
text
MD5: 2e39a7eb31cea878e849582cb252b7fe
SHA256: 2bc0390d55803c28a92a2166bba711c4da6a1e55098d27dae91f1f84f468b219
2160
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\DriverUpdate Help.lnk
lnk
MD5: 96a57ff00a22ed4b4edaa1096fc52065
SHA256: e1fe7aac7d2a75d04ac5500c07eb8f116b62bc45905e49a7577c21d878be4749
2160
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\DriverUpdate.lnk
lnk
MD5: 96f32df3391397eb144194ff977fad47
SHA256: 3ef3a3e2d9620dbcac9a8dc87eadebf8402fde5f8307990797e60baa4d5892f3
2160
msiexec.exe
C:\Windows\Installer\MSI6DCB.tmp
binary
MD5: e35d605514f50bd21ac4790be8f98147
SHA256: 556e743b1f19a7592b82232f2f2b06bda4439e5d6f5caf1780dd6bddfe9ffc0f
2160
msiexec.exe
C:\Config.Msi\116aff.rbs
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Windows\Installer\116afe.ipi
binary
MD5: 6eea2b9893603ecac3ea76b8d9160d18
SHA256: b4defb1b69454fca7f8da2cf6d82231b9d6ae0ea165842e72ca2655d56cb1f5d
2160
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DFE6E3D7508F64DAAF.TMP
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Windows\Installer\MSI6CC1.tmp
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Windows\Installer\116afc.msi
––
MD5:  ––
SHA256:  ––
3552
DriverUpdate-setup.exe
C:\Users\admin\AppData\Local\Downloaded Installers\{B1B1FD0A-FF2A-4157-A086-CAC980E8AB0A}\setup.msi
––
MD5:  ––
SHA256:  ––
3552
DriverUpdate-setup.exe
C:\Users\admin\AppData\Local\Temp\SIOUT1140328\DriverUpdate-setup.msi
––
MD5:  ––
SHA256:  ––
2160
msiexec.exe
C:\Program Files\DriverUpdate\DriverUpdate.exe
––
MD5:  ––
SHA256:  ––
3572
SlimCleanerPlus.exe
C:\Users\admin\AppData\Local\Temp\SWI4F46.tmp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
4
TCP/UDP connections
4
DNS requests
4
Threats
2

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3572 SlimCleanerPlus.exe GET 200 54.164.207.74:80 http://stc.slimwareutilities.com/gettrack?product=SW2 US
––
––
malicious
3572 SlimCleanerPlus.exe GET 200 52.7.3.6:80 http://trk.slimwareutilities.com/ulc.php?ev=InstallerInvoked&platformOSVersion=6.1&ul_stubid=097705DC-A0B0-4775-BFB5-DDDCF14B8204&installer=SD0&product=SW2&installerVersion=2.4.1&machineId=CE120B9A-F7A4-4AD7-82E2-0523B06839AB&platformOS=Windows US
text
malicious
3572 SlimCleanerPlus.exe GET 200 13.249.12.202:80 http://download.driverupdate.net/5.8.8/x86/DriverUpdate-setup.exe US
executable
whitelisted
3572 SlimCleanerPlus.exe GET 200 52.7.3.6:80 http://trk.slimwareutilities.com/ulc.php?ev=InstallerFinished&platformOSVersion=6.1&installId=BFD6040A-5109-441F-A081-A27BB3837720&ul_stubid=097705DC-A0B0-4775-BFB5-DDDCF14B8204&installer=SD0&product=SW2&installerVersion=2.4.1&machineId=CE120B9A-F7A4-4AD7-82E2-0523B06839AB&platformOS=Windows US
text
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3572 SlimCleanerPlus.exe 54.164.207.74:80 Amazon.com, Inc. US malicious
3572 SlimCleanerPlus.exe 54.86.231.162:80 Amazon.com, Inc. US malicious
3572 SlimCleanerPlus.exe 52.7.3.6:80 Amazon.com, Inc. US malicious
3572 SlimCleanerPlus.exe 13.249.12.202:80 US suspicious

DNS requests

Domain IP Reputation
stc.slimwareutilities.com 54.164.207.74
52.4.3.53
malicious
apps-api.slimwareutilities.com 54.86.231.162
54.158.10.23
3.208.14.245
malicious
trk.slimwareutilities.com 52.7.3.6
52.5.68.22
34.236.116.104
malicious
download.driverupdate.net 13.249.12.202
13.249.12.38
13.249.12.119
13.249.12.15
whitelisted

Threats

PID Process Class Message
3572 SlimCleanerPlus.exe Potentially Bad Traffic ET POLICY Executable served from Amazon S3
3572 SlimCleanerPlus.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP

Debug output strings

No debug info.