General Info

File name

EMMSetup.exe

Full analysis
https://app.any.run/tasks/0d163014-4961-4752-8f71-f3b42d471e08
Verdict
Malicious activity
Analysis date
7/11/2019, 16:15:29
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

7b7dd95bf9f2bca3bfb90e396041b926

SHA1

67ce8582892d870f46e518e597e4276c5d370769

SHA256

76e5b07cc2c9b0c954341174c4023c269b1534599adae88f395e26175c8cde31

SSDEEP

393216:Y2EeLIBhInp4uBR4hGW7KFPwdqR8mDcrL:gNBhInp4yR4POWrmDm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • OUTLOOK.EXE (PID: 2724)
Creates files in the user directory
  • OUTLOOK.EXE (PID: 2724)
  • EMMSetup.exe (PID: 3584)
Reads Internet Cache Settings
  • OUTLOOK.EXE (PID: 2724)
Reads the BIOS version
  • OUTLOOK.EXE (PID: 2724)
Creates files in the program directory
  • OUTLOOK.EXE (PID: 2724)
Reads internet explorer settings
  • OUTLOOK.EXE (PID: 2724)
Creates COM task schedule object
  • msiexec.exe (PID: 3040)
Executed via COM
  • DrvInst.exe (PID: 3540)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 3040)
  • EMMSetup.exe (PID: 3584)
Executed as Windows Service
  • vssvc.exe (PID: 2608)
Dropped object may contain Bitcoin addresses
  • EMMSetup.exe (PID: 3584)
  • msiexec.exe (PID: 3040)
Loads dropped or rewritten executable
  • MsiExec.exe (PID: 3132)
  • MsiExec.exe (PID: 2948)
  • MsiExec.exe (PID: 3972)
Creates a software uninstall entry
  • msiexec.exe (PID: 3040)
Creates files in the program directory
  • msiexec.exe (PID: 3040)
  • MsiExec.exe (PID: 2948)
Searches for installed software
  • msiexec.exe (PID: 3040)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 2608)
Reads Microsoft Office registry keys
  • OUTLOOK.EXE (PID: 2724)
Application launched itself
  • msiexec.exe (PID: 3040)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (76.4%)
.exe
|   Win32 Executable (generic) (12.4%)
.exe
|   Generic Win/DOS Executable (5.5%)
.exe
|   DOS Executable Generic (5.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:12:04 23:06:00+01:00
PEType:
PE32
LinkerVersion:
14.16
CodeSize:
2351616
InitializedDataSize:
1555968
UninitializedDataSize:
null
EntryPoint:
0x1d848d
OSVersion:
6
ImageVersion:
null
SubsystemVersion:
6
Subsystem:
Windows GUI
FileVersionNumber:
1.0.0.1
ProductVersionNumber:
1.0.0.1
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
DS Development
FileDescription:
Setup Launcher Utility
FileVersion:
1.0.0.1
InternalName:
SetupLauncher.exe
LegalCopyright:
(c) DS Development. All rights reserved.
OriginalFileName:
SetupLauncher.exe
ProductName:
Setup Launcher Utility
ProductVersion:
1.0.0.1
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
04-Dec-2018 22:06:00
Detected languages
English - United States
TLS Callbacks:
1 callback(s) detected.
Debug artifacts
f:\work\CommonLibs\SetupLauncher\Release\SetupLauncher.pdb
CompanyName:
DS Development
FileDescription:
Setup Launcher Utility
FileVersion:
1.0.0.1
InternalName:
SetupLauncher.exe
LegalCopyright:
(c) DS Development. All rights reserved.
OriginalFilename:
SetupLauncher.exe
ProductName:
Setup Launcher Utility
ProductVersion:
1.0.0.1
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000120
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
04-Dec-2018 22:06:00
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0023E061 0x0023E200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.62656
.rdata 0x00240000 0x0008DE68 0x0008E000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.29003
.data 0x002CE000 0x00025F00 0x00020800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.53438
.rsrc 0x002F4000 0x000A7178 0x000A7200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.02583
.reloc 0x0039C000 0x00020BEC 0x00020C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.56088
Resources
1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

37

38

39

40

41

42

43

44

45

46

47

48

49

50

51

52

53

54

55

56

57

58

59

60

61

62

63

64

65

66

67

68

69

70

71

72

73

74

129

130

329

5250

5251

5255

5258

5259

5260

5261

5262

5263

5265

5266

5268

5269

5270

5272

5273

5274

5275

5276

5278

5279

Imports
    VERSION.dll

    msi.dll

    WINHTTP.dll

    KERNEL32.dll

    USER32.dll

    GDI32.dll

    ADVAPI32.dll

    SHELL32.dll

    ole32.dll

    OLEAUT32.dll

    SHLWAPI.dll

    WS2_32.dll

    CRYPT32.dll

    bcrypt.dll

Exports

    No exports.

Screenshots

Processes

Total processes
45
Monitored processes
8
Malicious processes
1
Suspicious processes
1

Behavior graph

+
start emmsetup.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs outlook.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3584
CMD
"C:\Users\admin\AppData\Local\Temp\EMMSetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\EMMSetup.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
DS Development
Description
Setup Launcher Utility
Version
1.0.0.1
Modules
Image
c:\users\admin\appdata\local\temp\emmsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\msihnd.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\riched20.dll
c:\progra~1\micros~1\office14\outlook.exe
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll

PID
3040
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll

PID
3972
CMD
C:\Windows\system32\MsiExec.exe -Embedding 1543E2B1B603DEA1A7B727BB4D455624 C
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\msi5e75.tmp
c:\progra~1\micros~1\office14\outlook.exe
c:\users\admin\appdata\local\temp\msi5f41.tmp

PID
2608
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll

PID
3540
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot21" "" "" "6f9bf5bcb" "00000000" "000005C0" "000002B4"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
3132
CMD
C:\Windows\system32\MsiExec.exe -Embedding A05E53F1B66342F20E4E1829C7CEC052
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msid5f7.tmp
c:\progra~1\micros~1\office14\outlook.exe
c:\windows\installer\msid899.tmp
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\installer\msid907.tmp
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2948
CMD
C:\Windows\system32\MsiExec.exe -Embedding D9D45F46C15EFCC99FD02260D0DB49AD M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msidcf1.tmp
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll

PID
2724
CMD
"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE"
Path
C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE
Indicators
Parent process
EMMSetup.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Outlook
Version
14.0.6025.1000
Modules
Image
c:\progra~1\micros~1\office14\outlook.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\system32\apphelp.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\microsoft office\office14\addins\umoutlookaddin.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimtf.dll
c:\progra~1\micros~1\office14\1033\outllibr.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\progra~1\micros~1\office14\olmapi32.dll
c:\progra~1\micros~1\office14\1033\mapir.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\progra~1\micros~1\office14\wwlib.dll
c:\progra~1\micros~1\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\progra~1\micros~1\office14\oart.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\progra~1\micros~1\office14\contab32.dll
c:\progra~1\micros~1\office14\omsxp32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\mspst32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\program files\microsoft office\office14\addins\colleagueimport.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\program files\ds development\easy mail merge for outlook\emmaddin.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\tquery.dll
c:\windows\system32\profapi.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\propsys.dll
c:\program files\microsoft office\office14\onbttnol.dll
c:\program files\microsoft office\office14\socialconnector.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\mfc90enu.dll
c:\windows\system32\mapi32.dll
c:\program files\microsoft office\office14\1033\umoutlookstrings.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\adsldp.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\atl.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\program files\microsoft office\office14\sharepointprovider.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\windowscodecs.dll
c:\progra~1\micros~1\office14\outlctl.dll
c:\windows\system32\jscript.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\program files\common files\system\ole db\oledb32.dll
c:\windows\system32\msdart.dll
c:\program files\common files\system\ole db\oledb32r.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\msiltcfg.dll
c:\progra~1\micros~1\office14\omsmain.dll
c:\windows\system32\winmm.dll
c:\progra~1\micros~1\office14\outlacct.dll
c:\windows\system32\msident.dll
c:\windows\system32\pstorec.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\tzres.dll
c:\windows\system32\pngfilt.dll

Registry activity

Total events
1683
Read events
1192
Write events
467
Delete events
24

Modification events

PID
Process
Operation
Key
Name
Value
3584
EMMSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3040
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3040
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3040
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70\52C64B7E
3040
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70
3040
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3040
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000DC918D39F337D501E00B00006C090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
4000000000000000DC918D39F337D501E00B00006C090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
23
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
4000000000000000CA29073AF337D501E00B00006C090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
40000000000000007EEE0B3AF337D501E00B000060010000E8030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000EC1C1E3BF337D501E00B000060010000E8030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
4000000000000000A89E7942F337D501E00B00006C090000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
4000000000000000E03A9642F337D501E00B00005C0D0000E9030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
40000000000000003425C142F337D501E00B00005C0D0000E9030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
40000000000000003425C142F337D501E00B00009C0D0000F9030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
4000000000000000CA645F42F337D501E00B00006C090000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
4000000000000000CA645F42F337D501E00B00006C090000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
4000000000000000AAD5D142F337D501E00B00009C0D0000F9030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
4000000000000000B8FCD842F337D501E00B00006C0900000A040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
40000000000000000C143544F337D501E00B0000A40D00000A040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
40000000000000000C143544F337D501E00B00006C090000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
400000000000000066763744F337D501E00B00006C090000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
23
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
DC918D39F337D501
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
E00B00002AF6B932F337D501
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
F82A0323E0BCCE5D3592A8F76E43D9AFA54CB8D6650903890BAD1E8BF46F5BE9
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\15cdda.ipi
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\15cddb.rbs
30750715
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\15cddb.rbsLow
2814583360
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\272FEF2716C874F499344D3A3B14B0D3
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMAddin.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7162305D25F37164D82332942AFFB03E
3FE6F2881F3A42A448CAC923FCEED2CA
01:\Software\Microsoft\Office\Outlook\Addins\EMMAddin.Connect\FriendlyName
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC7D7F0C5FE3BC488A839BBD7E27683
3FE6F2881F3A42A448CAC923FCEED2CA
02:\Software\DS Development\EasyMailMergeAddin\EMMEnabled
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCF7D4C5B99F1FC459264E66D453C1A6
3FE6F2881F3A42A448CAC923FCEED2CA
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\40C0A2D5E50E9AE4DB68DC1FD49C35A6
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMData.exe
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76FB5A8AAD0C46F46BB5F5C9D1DFF929
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\UpgradeData.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8EAB8D6FE32EACD44B6C87EAB63531B8
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\emm.chm
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DAEF7862CDCCCEA4FBEBC0306252DEF3
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\Eula.txt
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1380E4C19DEB211498DD7649B467B3BE
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\ScriptHelper.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\92519A4684D1ACD4F8CAC5985BFC7E38
3FE6F2881F3A42A448CAC923FCEED2CA
C:\Program Files\DS Development\Easy Mail Merge for Outlook\emm_folder.htm
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\66280C82D1BE3DC4FA9B5BB73B85CE79
3FE6F2881F3A42A448CAC923FCEED2CA
01:\Software\DS Development\EasyMailMergeAddin\CommonInstalled
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\211F2F5E06097A94CB3A29001ED02047
3FE6F2881F3A42A448CAC923FCEED2CA
01:\Software\DS Development\EasyMailMergeAddin\AddinInstalled
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4A5DE5CF9C21A546B83B4C331337C63
3FE6F2881F3A42A448CAC923FCEED2CA
01:\Software\DS Development\EasyMailMergeAddin\HelpInstalled
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS Development\Easy Mail Merge for Outlook\
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS Development\
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\DS Development\Easy Mail Merge for Outlook\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\DS Development\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.Connect
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.Connect\CLSID
{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}\VersionIndependentProgID
EMMAddin.Connect
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.Connect\CurVer
EMMAddin.Connect.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.Connect.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.Connect.1\CLSID
{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}\ProgID
EMMAddin.Connect.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}\InprocServer32
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMAddin.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}\InprocServer32
ThreadingModel
Apartment
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41F170C4-BAC5-4A43-ACAF-617E59A0E17B}\TypeLib
{2334A27F-2395-40A1-A032-0DF216E7DB7B}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E5C2810-2F82-495D-A0B2-0C42CE4900CD}
IListCtrl
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E5C2810-2F82-495D-A0B2-0C42CE4900CD}\TypeLib
{2334A27F-2395-40A1-A032-0DF216E7DB7B}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E5C2810-2F82-495D-A0B2-0C42CE4900CD}\TypeLib
Version
1.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E5C2810-2F82-495D-A0B2-0C42CE4900CD}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D460451-EBD8-4FA8-849E-4C9787E77DBC}
IEACSession
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D460451-EBD8-4FA8-849E-4C9787E77DBC}\TypeLib
{2334A27F-2395-40A1-A032-0DF216E7DB7B}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D460451-EBD8-4FA8-849E-4C9787E77DBC}\TypeLib
Version
1.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D460451-EBD8-4FA8-849E-4C9787E77DBC}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{67C62D40-EF03-496F-8174-0CEEF3FA1C8B}
IOperationProgress
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{67C62D40-EF03-496F-8174-0CEEF3FA1C8B}\TypeLib
{2334A27F-2395-40A1-A032-0DF216E7DB7B}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{67C62D40-EF03-496F-8174-0CEEF3FA1C8B}\TypeLib
Version
1.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{67C62D40-EF03-496F-8174-0CEEF3FA1C8B}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2334A27F-2395-40A1-A032-0DF216E7DB7B}\1.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2334A27F-2395-40A1-A032-0DF216E7DB7B}\1.0\0\win32
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMAddin.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2334A27F-2395-40A1-A032-0DF216E7DB7B}\1.0\FLAGS
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{83B84A18-F986-4524-9818-120F20027CDD}
ISessionData
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{83B84A18-F986-4524-9818-120F20027CDD}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{83B84A18-F986-4524-9818-120F20027CDD}\TypeLib
Version
1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{83B84A18-F986-4524-9818-120F20027CDD}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FD41A4D-5C3D-410B-915C-CA3BAE8B3265}\LocalServer32
"C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMData.exe"
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FD41A4D-5C3D-410B-915C-CA3BAE8B3265}\LocalServer32
ThreadingModel
Free
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FD41A4D-5C3D-410B-915C-CA3BAE8B3265}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F004592E-3D7E-4A76-A94E-5DA898E82FD1}
ISessionBrowser
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F004592E-3D7E-4A76-A94E-5DA898E82FD1}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F004592E-3D7E-4A76-A94E-5DA898E82FD1}\TypeLib
Version
1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F004592E-3D7E-4A76-A94E-5DA898E82FD1}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EA482437-CB22-40E8-B693-8BF386D6B228}\LocalServer32
"C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMData.exe"
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EA482437-CB22-40E8-B693-8BF386D6B228}\LocalServer32
ThreadingModel
Free
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EA482437-CB22-40E8-B693-8BF386D6B228}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{64706739-EA1F-4FE3-B283-C9F74148DF6F}
IInsertRecipients
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{64706739-EA1F-4FE3-B283-C9F74148DF6F}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{64706739-EA1F-4FE3-B283-C9F74148DF6F}\TypeLib
Version
1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{64706739-EA1F-4FE3-B283-C9F74148DF6F}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{966530E2-1BEC-4DDB-A643-0AEBFF24C60C}
IInsertContact
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{966530E2-1BEC-4DDB-A643-0AEBFF24C60C}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{966530E2-1BEC-4DDB-A643-0AEBFF24C60C}\TypeLib
Version
1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{966530E2-1BEC-4DDB-A643-0AEBFF24C60C}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{615E22B4-17AB-45A0-8997-D8EC1AAE104E}
IEmailCheck
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{615E22B4-17AB-45A0-8997-D8EC1AAE104E}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{615E22B4-17AB-45A0-8997-D8EC1AAE104E}\TypeLib
Version
1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{615E22B4-17AB-45A0-8997-D8EC1AAE104E}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A2612CE-A772-46BA-BB71-B773BC47317E}
IRecordRemove
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A2612CE-A772-46BA-BB71-B773BC47317E}\TypeLib
{81248B43-8F09-4D57-8981-1510794A84E1}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A2612CE-A772-46BA-BB71-B773BC47317E}\TypeLib
Version
1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A2612CE-A772-46BA-BB71-B773BC47317E}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{81248B43-8F09-4D57-8981-1510794A84E1}\1.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{81248B43-8F09-4D57-8981-1510794A84E1}\1.1\0\win32
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMData.exe
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{81248B43-8F09-4D57-8981-1510794A84E1}\1.1\FLAGS
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.ScriptHelper
Easy Mail Merge script helper class
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.ScriptHelper\CLSID
{D39A546B-D50F-4134-9EB9-C247832946E2}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D39A546B-D50F-4134-9EB9-C247832946E2}\VersionIndependentProgID
EMMAddin.ScriptHelper
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.ScriptHelper\CurVer
EMMAddin.ScriptHelper.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.ScriptHelper.1
Easy Mail Merge script helper class
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EMMAddin.ScriptHelper.1\CLSID
{D39A546B-D50F-4134-9EB9-C247832946E2}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D39A546B-D50F-4134-9EB9-C247832946E2}\ProgID
EMMAddin.ScriptHelper.1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D39A546B-D50F-4134-9EB9-C247832946E2}\InprocServer32
C:\Program Files\DS Development\Easy Mail Merge for Outlook\ScriptHelper.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D39A546B-D50F-4134-9EB9-C247832946E2}\InprocServer32
ThreadingModel
Apartment
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D39A546B-D50F-4134-9EB9-C247832946E2}\TypeLib
{C410E7E1-4C4E-4767-8EA7-08816B24B6D9}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{974979BC-A166-4ECC-9E67-92A690F189FC}
IEMMHelper
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{974979BC-A166-4ECC-9E67-92A690F189FC}\TypeLib
{C410E7E1-4C4E-4767-8EA7-08816B24B6D9}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{974979BC-A166-4ECC-9E67-92A690F189FC}\TypeLib
Version
1.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{974979BC-A166-4ECC-9E67-92A690F189FC}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C410E7E1-4C4E-4767-8EA7-08816B24B6D9}\1.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C410E7E1-4C4E-4767-8EA7-08816B24B6D9}\1.0\0\win32
C:\Program Files\DS Development\Easy Mail Merge for Outlook\ScriptHelper.dll
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C410E7E1-4C4E-4767-8EA7-08816B24B6D9}\1.0\FLAGS
0
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
FriendlyName
Easy Mail Merge
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
Description
Easy Mail Merge for Outlook Addin
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
LoadBehavior
3
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
CommandLineSafe
0
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\DS Development\EasyMailMergeAddin
CommonInstalled
1
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\DS Development\EasyMailMergeAddin
AddinInstalled
1
3040
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\DS Development\EasyMailMergeAddin
HelpInstalled
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
FriendlyName
Easy Mail Merge
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
Description
Easy Mail Merge for Outlook Addin
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
LoadBehavior
3
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\EMMAddin.Connect
CommandLineSafe
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\DS Development\EasyMailMergeAddin
EMMEnabled
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
LocalPackage
C:\Windows\Installer\15cddc.msi
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
AuthorizedCDFPrefix
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Comments
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Contact
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
DisplayVersion
5.0.466.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
HelpLink
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
HelpTelephone
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
InstallDate
20190711
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
InstallLocation
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
InstallSource
C:\ProgramData\DS Development\SetupCache\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
ModifyPath
MsiExec.exe /I{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Publisher
DS Development
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Readme
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Size
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
EstimatedSize
17303
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
UninstallString
MsiExec.exe /I{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
URLInfoAbout
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
URLUpdateInfo
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
VersionMajor
5
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
VersionMinor
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
WindowsInstaller
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Version
83886546
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
Language
1033
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
AuthorizedCDFPrefix
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Comments
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Contact
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
DisplayVersion
5.0.466.0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
HelpLink
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
HelpTelephone
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
InstallDate
20190711
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
InstallLocation
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
InstallSource
C:\ProgramData\DS Development\SetupCache\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
ModifyPath
MsiExec.exe /I{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Publisher
DS Development
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Readme
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Size
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
EstimatedSize
17303
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
UninstallString
MsiExec.exe /I{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
URLInfoAbout
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
URLUpdateInfo
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
VersionMajor
5
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
VersionMinor
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
WindowsInstaller
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Version
83886546
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
Language
1033
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\9BF6F099B04B34A47B7A51AADB5CC8DC
3FE6F2881F3A42A448CAC923FCEED2CA
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\InstallProperties
DisplayName
Easy Mail Merge for Outlook
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}
DisplayName
Easy Mail Merge for Outlook
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\3FE6F2881F3A42A448CAC923FCEED2CA
common
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\Features
common
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\3FE6F2881F3A42A448CAC923FCEED2CA
Addin
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\Features
Addin
T_WzLWGoPA!b^`]fX`]7=0=[email protected]=T!&S?eua{qOq2}'u4M`@[email protected][aEQy'[email protected](I,,n+Jk90yE`[email protected]'okevR8h2JH==5_x?ySA2Sw9Zvc^-W([^H0_lr)@awB}!KiIV8wj9+,[email protected][tuAxEHPQ-!AJ0Y0ToYSIRZxyur`a1b?q-`[email protected]
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\3FE6F2881F3A42A448CAC923FCEED2CA
Documentation
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\Features
Documentation
F}XDxbO5!Av{G)a+&IdT'q0][email protected]=Ib1H7m[P[5
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE6F2881F3A42A448CAC923FCEED2CA\Patches
AllPatches
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
ProductName
Easy Mail Merge for Outlook
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
PackageCode
07E90A611DE54F24A82486D0321634F6
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
Language
1033
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
Version
83886546
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
Assignment
1
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
AdvertiseFlags
388
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
ProductIcon
C:\Windows\Installer\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}\logo.ico
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
InstanceType
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
AuthorizedLUAApp
0
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
DeploymentFlags
2
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\9BF6F099B04B34A47B7A51AADB5CC8DC
3FE6F2881F3A42A448CAC923FCEED2CA
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA\SourceList
PackageName
EMMSetup.msi
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA\SourceList\Net
1
C:\ProgramData\DS Development\SetupCache\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA\SourceList\Media
1
;
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA
Clients
:
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3FE6F2881F3A42A448CAC923FCEED2CA\SourceList
LastUsedSource
n;1;C:\ProgramData\DS Development\SetupCache\
3040
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
113
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
400000000000000002C6233AF337D501300A000010090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
400000000000000002C6233AF337D501300A0000740C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
400000000000000002C6233AF337D501300A000004090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000002C6233AF337D501300A0000780C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000C4B12F3AF337D501300A000004090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000C4B12F3AF337D501300A0000780C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000D2D8363AF337D501300A0000740C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000869D3B3AF337D501300A000010090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
4000000000000000E03A9642F337D501300A00001009000001040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
4000000000000000E03A9642F337D501300A00001009000001040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000A226A242F337D501300A0000780C0000E9030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000A226A242F337D501300A0000740C0000E9030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000A226A242F337D501300A000010090000E9030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
400000000000000056EBA642F337D501300A0000780C0000E9030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000056EBA642F337D501300A0000780C000001000000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
400000000000000056EBA642F337D501300A000010090000E9030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000056EBA642F337D501300A00001009000001000000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
4000000000000000B04DA942F337D501300A0000740C0000E9030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000B04DA942F337D501300A0000740C000001000000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
40000000000000005073CF42F337D501300A0000780C0000F9030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
40000000000000005073CF42F337D501300A0000740C0000F9030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
40000000000000005073CF42F337D501300A000010090000F9030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
40000000000000005073CF42F337D501300A000010090000F9030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
40000000000000005073CF42F337D501300A0000740C0000F9030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
4000000000000000AAD5D142F337D501300A0000780C0000F9030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
4000000000000000B8FCD842F337D501300A0000B40D000002040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000CA919043F337D501300A0000B40D000002040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
4000000000000000CA919043F337D501300A0000B40D0000EA030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
4000000000000000E6DF9E43F337D501300A0000780D0000EA030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
4000000000000000E6DF9E43F337D501300A0000940D0000EA030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
4000000000000000E6DF9E43F337D501300A0000A00D0000EA030000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
40000000000000001E7CBB43F337D501300A0000A00D0000EA030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
40000000000000001E7CBB43F337D501300A0000A00D000002000000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
4000000000000000D240C043F337D501300A0000940D0000EA030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000D240C043F337D501300A0000940D000002000000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
4000000000000000D240C043F337D501300A0000780D0000EA030000000000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000D240C043F337D501300A0000780D000002000000010000000100000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
4000000000000000808DED43F337D501300A0000B40D0000EA030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
4000000000000000808DED43F337D501300A0000B40D0000EB030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
4000000000000000808DED43F337D501300A0000B40D0000EC030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
40000000000000003452F243F337D501300A0000A00D0000EB030000010000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
40000000000000003452F243F337D501300A0000A00D0000EB030000000000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000003452F243F337D501300A0000A00D000003000000010000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000003452F243F337D501300A0000040F0000FC030000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
40000000000000003452F243F337D501300A0000B40D0000EC030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
40000000000000003452F243F337D501300A0000B40D0000ED030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
40000000000000004279F943F337D501300A0000B40D0000ED030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
40000000000000004279F943F337D501300A0000B40D0000EE030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
4000000000000000F63DFE43F337D501300A0000780D0000EB030000010000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
4000000000000000F63DFE43F337D501300A0000780D0000EB030000000000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000F63DFE43F337D501300A0000780D000003000000010000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000F63DFE43F337D501300A00003C0F0000FC030000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
4000000000000000AA020344F337D501300A0000B40D0000EE030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
4000000000000000AA020344F337D501300A0000B40D0000F0030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
4000000000000000AA020344F337D501300A0000B40D0000F0030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
4000000000000000AA020344F337D501300A0000B40D0000EF030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
40000000000000005EC70744F337D501300A0000A00D0000EB030000010000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
400000000000000020B31344F337D501300A0000A00D0000EB030000000000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
400000000000000020B31344F337D501300A0000A00D000003000000010000000200000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
400000000000000020B31344F337D501300A000000010000FC030000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
400000000000000020B31344F337D501300A0000B40D0000EF030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
400000000000000020B31344F337D501300A0000B40D0000EB030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
400000000000000020B31344F337D501300A0000B40D000003040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
400000000000000020B31344F337D501300A0000B40D000003040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
400000000000000020B31344F337D501300A0000B40D0000FD030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
400000000000000020B31344F337D501300A00002C090000FD030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
400000000000000096632444F337D501300A00002C090000FD030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
400000000000000096632444F337D501300A0000B40D0000FD030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000096632444F337D501300A00002C090000FE030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
4000000000000000B2B13244F337D501300A00002C090000FE030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
4000000000000000B2B13244F337D501300A00002C090000FF030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
4000000000000000B2B13244F337D501300A00002C090000FF030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000096632444F337D501300A0000B40D0000FE030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
4000000000000000B2B13244F337D501300A0000B40D0000FE030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
4000000000000000B2B13244F337D501300A0000B40D0000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
4000000000000000B2B13244F337D501300A0000B40D0000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
4000000000000000B2B13244F337D501300A0000EC08000004040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
4000000000000000B2B13244F337D501300A0000EC08000004040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
4000000000000000B2B13244F337D501300A0000B40D000005040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
40000000000000000C143544F337D501300A0000B40D000005040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
40000000000000000C143544F337D501300A0000B40D0000F4030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
40000000000000000C143544F337D501300A0000B40D0000F4030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
40000000000000000C143544F337D501300A0000B40D0000F2030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
4000000000000000749D3E44F337D501300A00009C0D0000F2030000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000749D3E44F337D501300A0000040F0000FC030000000000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
4000000000000000749D3E44F337D501300A00009C0D0000F2030000000000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
4000000000000000749D3E44F337D501300A00009C0D000004000000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
4000000000000000749D3E44F337D501300A0000780D0000F2030000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000749D3E44F337D501300A000000010000FC030000000000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
4000000000000000749D3E44F337D501300A0000780D0000F2030000000000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
4000000000000000749D3E44F337D501300A00008C010000F2030000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
4000000000000000749D3E44F337D501300A0000780D000004000000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000749D3E44F337D501300A00003C0F0000FC030000000000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
4000000000000000749D3E44F337D501300A00008C010000F2030000000000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
4000000000000000749D3E44F337D501300A00008C01000004000000010000000300000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
4000000000000000749D3E44F337D501300A0000B40D0000F2030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
4000000000000000749D3E44F337D501300A0000B40D000006040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
40000000000000002A999B44F337D501300A0000B40D000006040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
40000000000000002A999B44F337D501300A0000B40D0000F5030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
4000000000000000AE70B344F337D501300A0000980D0000F5030000010000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
4000000000000000AE70B344F337D501300A00009C0D0000F5030000010000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
4000000000000000AE70B344F337D501300A0000940D0000F5030000010000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
4000000000000000AE70B344F337D501300A0000980D0000F5030000000000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000AE70B344F337D501300A0000980D000005000000010000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
400000000000000008D3B544F337D501300A00009C0D0000F5030000000000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
400000000000000008D3B544F337D501300A00009C0D000005000000010000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
4000000000000000924FD645F337D501300A0000940D0000F5030000000000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000924FD645F337D501300A0000940D000005000000010000000400000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
4000000000000000924FD645F337D501300A0000B40D0000F5030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
4000000000000000924FD645F337D501300A0000B40D000007040000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
4000000000000000244EF545F337D501300A0000B40D000007040000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
4000000000000000F4600846F337D501300A0000B40D0000FB030000010000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
40000000000000005CEA1146F337D501300A0000940D0000FB030000010000000500000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
40000000000000005CEA1146F337D501300A0000940D0000FB030000000000000500000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
40000000000000005CEA1146F337D501300A0000A00D0000FB030000010000000500000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
40000000000000005CEA1146F337D501300A0000A00D0000FB030000000000000500000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
40000000000000005CEA1146F337D501300A00008C010000FB030000010000000500000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
40000000000000005CEA1146F337D501300A00008C010000FB030000000000000500000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
2608
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
40000000000000005CEA1146F337D501300A0000B40D0000FB030000000000000000000000000000EAAFC2ED5606F849A5888A625565B7820000000000000000
3540
DrvInst.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2724
OUTLOOK.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
2724
OUTLOOK.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019032320190324
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
?q?
3F713F00A40A0000010000000000000000000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook
MTTT
A40A000046F5D04BF337D50100000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM
SQMSessionNumber
0
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM
SQMSessionDate
220121280
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046
00030429
03000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
{ED475418-B0D6-11D2-8C3B-00104B2A6676}
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
LastChangeVer
1200000000000000
2724
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OutlookMAPI2Intl_1033
1324023829
2724
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
OUTLOOKFiles
1324023854
2724
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1324023952
2724
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OUTLOOKFilesIntl_1033
1324023831
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Display Types\Balloons
HWND64ForOrphanedNotIcon
8C000400
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
h?
687F3F00A40A0000020000000000000000010000010000008C0000006800000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0063006F006C006C006500610067007500650069006D0070006F00720074002E0064006C006C0000006D006900630072006F0073006F006600740020007300680061007200650070006F0069006E0074002000730065007200760065007200200063006F006C006C0065006100670075006500200069006D0070006F007200740020006100640064002D0069006E000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
u ?
75203F00A40A00000200000000000000BE00000001000000920000002000000063003A005C00700072006F006700720061006D002000660069006C00650073005C0064007300200064006500760065006C006F0070006D0065006E0074005C00650061007300790020006D00610069006C0020006D006500720067006500200066006F00720020006F00750074006C006F006F006B005C0065006D006D0061006400640069006E002E0064006C006C000000650061007300790020006D00610069006C0020006D0065007200670065000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
=!?
3D213F00A40A00000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
l!?
6C213F00A40A00000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
f"?
66223F00A40A00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\DS Development\EasyMailMergeAddin
TimestampVer2
ewoiZjAxIjogewoiY2VyZWFsX2NsYXNzX3ZlcnNpb24iOiAxLAoiZjAxIjogMjU2LAoiZjAy IjogIkJENlUvRlNjSkcvOW5uMUc1RW1HOU12M1NKQkNHMVVkQlBWOURKQ0hzdEZBeTA3MXZQ cTlvVnRLVzlNNnE1NnVTMGdsN0xnaWtML254dWFlMUtMSDNrVTV6QlhLVTRFZmltS1A2YzJ3 S0pBQ04wdGhudDhPOS9HUkNkRC9sQndxMXEyMEJqUVNVakFXNHlhaC9sc3ViUlR2R3NESHJo RTNLSkRldjUzNUhHWWx0SmlYR3QrL2hTUlFVQTlwODZ2RGV0NDNUZGIrVTVVNTU1dUJ2TUdL cThSbVB4aCt5cWxsVGhibmczKzA5REZSS0E3VGJzQno0WDlBbTROWkRVdFFYQ2crS2FLMFFy aEdCZVI2SlMrUGs0MFdVSDBYemEzUU9VeWtKNHZud2c1czR2bno3b0owNkFlYWVmV25peUds UHdxYUhmSUtYK0srQTVNejdac2g0UT09IiwKImYwMyI6IDE3NiwKImYwNCI6ICJHT292c3Ba Ykl4dklCVmowYzdqd2luUlNTOHhvVXViajRHWDdmc0pjNlBEWFFrTTZYNVhPTFp2Mk8yL2xO L1NKbXMxd0JUbnBCNEY1QVRyWEJjQVZlckVUR3BReU80TmVoMmNXN1JKRDRqR2l6WEo5MnJX b2UzOUJ4K1NSVnZUaHBuSld5TUFPL1I0VzFnZjR3dXNRRUMzYXMyY0JYZUtnaUppdytnZklH SHJqT0Z5NlFwbTk4cjZDLzU2QkQwTmJ4aG0zTEgrSGR2eWdCNnVQblV1b3c4TUlCRXVKSXAz VWdOSXNFWTFDdE5VPSIKfQp9
2724
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OUTLOOKFilesIntl_1033
1324023832
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
1#?
31233F00A40A00000200000000000000BE00000001000000920000002000000063003A005C00700072006F006700720061006D002000660069006C00650073005C0064007300200064006500760065006C006F0070006D0065006E0074005C00650061007300790020006D00610069006C0020006D006500720067006500200066006F00720020006F00750074006C006F006F006B005C0065006D006D0061006400640069006E002E0064006C006C000000650061007300790020006D00610069006C0020006D0065007200670065000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\CustomUIValidationCache
EMMAddin.Connect.Microsoft.Outlook.Explorer
3763140368
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
.$?
2E243F00A40A00000200000000000000BE00000001000000920000002000000063003A005C00700072006F006700720061006D002000660069006C00650073005C0064007300200064006500760065006C006F0070006D0065006E0074005C00650061007300790020006D00610069006C0020006D006500720067006500200066006F00720020006F00750074006C006F006F006B005C0065006D006D0061006400640069006E002E0064006C006C000000650061007300790020006D00610069006C0020006D0065007200670065000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
=$?
3D243F00A40A00000200000000000000BE00000001000000920000002000000063003A005C00700072006F006700720061006D002000660069006C00650073005C0064007300200064006500760065006C006F0070006D0065006E0074005C00650061007300790020006D00610069006C0020006D006500720067006500200066006F00720020006F00750074006C006F006F006B005C0065006D006D0061006400640069006E002E0064006C006C000000650061007300790020006D00610069006C0020006D0065007200670065000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
m$?
6D243F00A40A00000200000000000000BE00000001000000920000002000000063003A005C00700072006F006700720061006D002000660069006C00650073005C0064007300200064006500760065006C006F0070006D0065006E0074005C00650061007300790020006D00610069006C0020006D006500720067006500200066006F00720020006F00750074006C006F006F006B005C0065006D006D0061006400640069006E002E0064006C006C000000650061007300790020006D00610069006C0020006D0065007200670065000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
}$?
7D243F00A40A00000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
l$?
6C243F00A40A00000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
+$?
2B243F00A40A00000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
;$?
3B243F00A40A00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
+$?
2B243F00A40A00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Type
1
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Count
1
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Time
E307070004000B000E0011000700FC01
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Count
2
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Time
E307070004000B000E00110007000B02
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Count
3
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
CleanupFolder
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{749381C3-B52C-4763-B93A-091E7DB8FC60}
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
AlertTypes
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
RestartsSinceAlerts
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
AlertInsertStrings
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
9'?
39273F00A40A00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
('?
28273F00A40A00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071120190712
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071120190712
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071120190712
CachePrefix
:2019071120190712:
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071120190712
CacheLimit
8192
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071120190712
CacheOptions
11
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071120190712
CacheRepair
0
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Search
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
3668774
2724
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
OUTLOOKNonBootFiles
1324023812
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
LastChangeVer
1300000000000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
LastChangeVer
1400000000000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Identities
Identity Ordinal
2
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\3517490d76624c419a828607e2a54604
001f6000
4E006F004D00610069006C000000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046
00030487
19CC1E0D
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\AB3399AF5DFF614691B189348574BB41
WriterId
4744375
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\AB3399AF5DFF614691B189348574BB41
LastModification
D0BEC2805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\AB3399AF5DFF614691B189348574BB41
MsgEID
00000000EE353A6753D116479D0919B95E8B889A88001000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\44A3CCFFB8A0E644B2B573E3A1601ACC
WriterId
4744390
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\44A3CCFFB8A0E644B2B573E3A1601ACC
LastModification
D02FC5805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\44A3CCFFB8A0E644B2B573E3A1601ACC
MsgEID
00000000EE353A6753D116479D0919B95E8B889AA8001000
2724
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
LanguageList
en-US
2724
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
C:\Windows\system32,@tzres.dll,-260
(UTC) Dublin, Edinburgh, Lisbon, London
2724
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
C:\Windows\system32,@tzres.dll,-262
GMT Standard Time
2724
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
C:\Windows\system32,@tzres.dll,-261
GMT Daylight Time
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\1060DDAD78F31A43A0CC9DD0715B3820
WriterId
4744390
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\1060DDAD78F31A43A0CC9DD0715B3820
LastModification
D02FC5805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\1060DDAD78F31A43A0CC9DD0715B3820
MsgEID
00000000EE353A6753D116479D0919B95E8B889AC8001000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\6663BDF9B7AC914D95F694AA9FE3386C
WriterId
4744390
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\6663BDF9B7AC914D95F694AA9FE3386C
LastModification
D02FC5805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\6663BDF9B7AC914D95F694AA9FE3386C
MsgEID
00000000EE353A6753D116479D0919B95E8B889AE8001000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\85285D156C30DA4782FBB210E7A11784
WriterId
4744390
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\85285D156C30DA4782FBB210E7A11784
LastModification
D02FC5805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\85285D156C30DA4782FBB210E7A11784
MsgEID
00000000EE353A6753D116479D0919B95E8B889A08011000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\1D44B325CAA7C745B0BCED245435FB89
WriterId
4744390
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\1D44B325CAA7C745B0BCED245435FB89
LastModification
D02FC5805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\1D44B325CAA7C745B0BCED245435FB89
MsgEID
00000000EE353A6753D116479D0919B95E8B889A28011000
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\F67DBC2116DF434CB752A253D471EE38
WriterId
4744390
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\F67DBC2116DF434CB752A253D471EE38
LastModification
D02FC5805A48D401
2724
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\F67DBC2116DF434CB752A253D471EE38
MsgEID
00000000EE353A6753D116479D0919B95E8B889A48011000

Files activity

Executable files
8
Suspicious files
6
Text files
111
Unknown types
5

Dropped files

PID
Process
Filename
Type
3040
msiexec.exe
C:\Windows\Installer\MSIDCF1.tmp
executable
MD5: ba84dd4e0c1408828ccc1de09f585eda
SHA256: 3cff4ac91288a0ff0c13278e73b282a64e83d089c5a61a45d483194ab336b852
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\ScriptHelper.dll
executable
MD5: a5276b1356b5a06daf8c12424e7efab9
SHA256: 664d972275c5e03cf3c6e3a0d5e76a7ce5ab9f184530d6ceac4ff429daebfed6
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMData.exe
executable
MD5: 719429d8504f736f134719fd0a27f51b
SHA256: 46bd069a8370eb39b492a1b435e45203958c0f11f4134d5b98acc7b38e5912e3
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\EMMAddin.dll
executable
MD5: 97aa44781b4a66c2d02ad75fd42482b9
SHA256: e8b809e6ebf3c748a8d34d426e0167d79d731f87facc329b6020715c8c576498
3040
msiexec.exe
C:\Windows\Installer\MSID899.tmp
executable
MD5: ba84dd4e0c1408828ccc1de09f585eda
SHA256: 3cff4ac91288a0ff0c13278e73b282a64e83d089c5a61a45d483194ab336b852
3040
msiexec.exe
C:\Windows\Installer\MSID5F7.tmp
executable
MD5: 572187dcd2c8d25b0088a1e6b66c9a32
SHA256: 797b055ff8a54ec64452b8daa434c864551751bddfd596447da7a9a48325c209
3584
EMMSetup.exe
C:\Users\admin\AppData\Local\Temp\MSI5F41.tmp
executable
MD5: 572187dcd2c8d25b0088a1e6b66c9a32
SHA256: 797b055ff8a54ec64452b8daa434c864551751bddfd596447da7a9a48325c209
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\UpgradeData.dll
executable
MD5: e090cf908b76c3d31e80dc6b5b83579d
SHA256: 69aa3e7842976aad83b4c30abad428694f340e96a46a3eafe2591259d013b8c3
2948
MsiExec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS Development\Easy Mail Merge for Outlook\Easy Mail Merge on the Web.url
text
MD5: f139179b2fc206702243eea283f48bef
SHA256: 0121ecd9f2f5b2eb50ac6d30c9ddb92f8a36d5e1015188d6ba6c137c1664f010
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_AvailabilityOptions_2_44A3CCFFB8A0E644B2B573E3A1601ACC.dat
xml
MD5: eeaa832c12f20de6aaaa9c7b77626e72
SHA256: c4c9a90f2c961d9ee79cf08fbee647ed7de0202288e876c7baad00f4ca29ca16
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\EMMAddin_dll[2]
image
MD5: b69497801115517b3db1d24ec57097ee
SHA256: e3d385401f518915a0483a6026acd9a4a8e89bc33a983c8490d506f9dcd2169e
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\EMMAddin_dll[2]
image
MD5: 5824ec5f525c410fa3ed430567b81497
SHA256: 8af91f4d02cff143aa61054c701fa657cc064f0b0204966a5b7be0476b13008f
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EMMAddin_dll[2]
image
MD5: 3aa840864b080c7f469a4e46f4a56cd0
SHA256: e660d8474e4b9e7498664467540aa39561575d343c3be7c426385c97444e2468
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_Calendar_2_AB3399AF5DFF614691B189348574BB41.dat
xml
MD5: b21ed3bd946332ff6ebc41a87776c6bb
SHA256: b1aac4e817cd10670b785ef8e5523c4a883f44138e50486987dc73054a46f6f4
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EMMAddin_dll[1]
image
MD5: 902ad6916bf46e88f72df8bcd26447ba
SHA256: db5bf2215452be2bdcf2ab60b429ebe687bace16b9000e033cbec82b8198f01b
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\EMMAddin_dll[1]
image
MD5: 5720be9521e89238dd43eaf658a1cb61
SHA256: d7c4b739e00cf6e56eaae3688df6803c2c914097a8ab78cd1d4251ea7a9a90d3
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\EMMAddin_dll[1]
image
MD5: a7a27f53a9a57f30f9891a9c4b923cdc
SHA256: e7e6d9c198d6203f06b1c71e0b5c97df08139e6b47f2425e9faa6d2efbc4307d
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\EMMAddin_dll[1]
image
MD5: 0de55a5bc771535283ef6f224e81907d
SHA256: 190599c1e5d902b720b68f7640ef3f8a1c3fbc818b50eadcf77ec5242a6714b8
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071120190712\index.dat
dat
MD5: 623d107a3ccb8c638603cb4ee967f59f
SHA256: 3d1a5c4397b7ff8a0301f3df04de56d5d38533b4c4892ca67acba04d9073cdd0
2724
OUTLOOK.EXE
C:\ProgramData\DS Development\EMM\ld4.dat
text
MD5: a1150dd46575124148acb94bfc5ff84f
SHA256: b86d9c68f0b5bbf9e9080762a93ca4f68b6d0f060d6cc93043d5d16ac05c220d
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{749381C3-B52C-4763-B93A-091E7DB8FC60}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png
image
MD5: 7d80c0a7e3849818695eaf4989186a3c
SHA256: 72dc527d78a8e99331409803811cc2d287e812c008a1c869a6aea69d7a44b597
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\gap[1]
image
MD5: 96c4c871750d7ca05dfa18ce6a85d369
SHA256: 74441313bb1fb62500484443c4937e90d4e335351a4fcd12a9ac48448500e33e
2724
OUTLOOK.EXE
C:\ProgramData\DS Development\EMM\ld4.dat
text
MD5: ab50f5292df31df4fad2b92c74078d39
SHA256: 9dcf0a3ee16bbcf2e23c2dc47d2267e7ab36b1fcee35f821f1637025d78282df
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Temp\mso2262.tmp
html
MD5: a8934077843220a8e31367c7bbe15e6c
SHA256: a2db0201d36f07f3f99d1adf8b8eafb9cf9bb803d024fcc9327b77af56346861
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inf
text
MD5: 48dd6cae43ce26b992c35799fcd76898
SHA256: 7bfe1f3691e2b4fb4d61fbf5e9f7782fbe49da1342dbd32201c2cc8e540dbd1a
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Temp\CVR1590.tmp.cvr
––
MD5:  ––
SHA256:  ––
3584
EMMSetup.exe
C:\Users\admin\AppData\Roaming\DS Development\SetupLauncher\logs\SetupLauncher_0.log
text
MD5: 594f01de1180b6925f55ea305549a3bc
SHA256: a2325326bc61a9fae13557e1833831000b1f30a52dbcdb3afe98eb3fbd08aacf
3584
EMMSetup.exe
C:\Users\admin\AppData\Roaming\DS Development\SetupLauncher\SetupLauncher_0.log
––
MD5:  ––
SHA256:  ––
3584
EMMSetup.exe
C:\Users\admin\AppData\Roaming\DS Development\SetupLauncher\EMMSetup.log
text
MD5: 05c785da7898474bb64955dbf32f4d36
SHA256: 58b48cffea5db7f6fcf9e7b718ec5cedc6dcb3fbac449dbbcd10cad54843c303
3040
msiexec.exe
C:\Users\admin\AppData\Roaming\DS Development\SetupLauncher\EMMSetup.log
text
MD5: f9d9731ccba4f8af828a052cefa19b24
SHA256: 51b67ab49c188c76b4f0dea4fd3d84ad7db857c3c27af96dc54861b738e6e12c
3040
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF342F5AFE5ACBB8BE.TMP
––
MD5:  ––
SHA256:  ––
3040
msiexec.exe
C:\Windows\Installer\15cdda.ipi
––
MD5:  ––
SHA256:  ––
3040
msiexec.exe
C:\Config.Msi\15cddb.rbs
––
MD5:  ––
SHA256:  ––
3040
msiexec.exe
C:\Windows\Installer\15cddc.msi
––
MD5:  ––
SHA256:  ––
3584
EMMSetup.exe
C:\Users\admin\AppData\Local\Temp\{8B2BF0F6-153A-4EA7-BFCA-918523344472}\EMMSetup.msi
––
MD5:  ––
SHA256:  ––
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EMMAddin_dll[3]
image
MD5: 9dd551bd12ea5c661c11fdde2b52dab1
SHA256: 50f76974434ed1eed6dc594b3f9823282afbadebe137f42cf5d4a17eafaebb69
3040
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS Development\Easy Mail Merge for Outlook\End User Agreement.lnk
lnk
MD5: e191e83443b40915994408876fa4bd01
SHA256: f9eda9a731c1f4bf5b06a85369f18e97b657038fbeccd91659f6ece045a6bb2d
3040
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS Development\Easy Mail Merge for Outlook\Easy Mail Merge Help.lnk
lnk
MD5: f9b5b53bde4460320cb2c479bdd652d4
SHA256: f1c7add9cfe3c3e290d2cfbd1cb197bf336a37a71d17121a422411d950215c8a
3040
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS Development\Easy Mail Merge for Outlook\Uninstall Easy Mail Merge.lnk
lnk
MD5: 06d6c8a84ae5155ff04b83102df0ec87
SHA256: 072c108adcee01aee8844d556398b4f2cdc40ffa54e576845404bf5d8d1b7536
3040
msiexec.exe
C:\Windows\Installer\{882F6EF3-A3F1-4A24-84AC-9C32CFEE2DAC}\logo.ico
image
MD5: a527a0e05ed395893f8ccb99a62ee4e7
SHA256: e52285d63279852cc36896e93179536fc7820d6cece5d38dfc29a12fc664817f
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_TCPrefs_2_F67DBC2116DF434CB752A253D471EE38.dat
xml
MD5: f194b1fa12f9b6f46a47391fae8beec2
SHA256: fcd8d7e030be6ea7588e5c6cb568e3f1bdfc263942074b693942a27df9521a74
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\Eula.txt
text
MD5: cfd7a2c0999de74980474e661dd2333f
SHA256: f7a88103de9fa2460ac0ae7d68ef5a314fcf42b9f7eada2fa30696d8778f3ce9
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ConversationPrefs_2_1D44B325CAA7C745B0BCED245435FB89.dat
xml
MD5: 57f30b1bca811c2fcb81f4c13f6a927b
SHA256: 612bad93621991cb09c347ff01ec600b46617247d5c041311ff459e247d8c2d3
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ContactPrefs_2_85285D156C30DA4782FBB210E7A11784.dat
xml
MD5: bbcf400bd7ae536eb03054021d6a6398
SHA256: 383020065c1f31f4fb09f448599a6d5e532c390af4e5b8af0771fe17a23222ad
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_RssRule_2_6663BDF9B7AC914D95F694AA9FE3386C.dat
xml
MD5: d8b37ed0410fb241c283f72b76987f18
SHA256: 31e68049f6b7f21511e70cd7f2d95b9cf1354cf54603e8f47c1fc40f40b7a114
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\emm_folder.htm
html
MD5: a56bef1a5b3fd70c95855ba70366524e
SHA256: c9f362e12a44a5999afba6f75e743c7f16d8a4fdf632d31bdcbe646db57c067a
3040
msiexec.exe
C:\Program Files\DS Development\Easy Mail Merge for Outlook\emm.chm
chm
MD5: ed0ed8f714407961afe829395861c32c
SHA256: 20f4b907e0d2c7253663e4ed2b21f341ae5fcd8817229d697f9a3883b67cb4ed
2608
vssvc.exe
C:
––
MD5:  ––
SHA256:  ––
3040
msiexec.exe
C:\Windows\Installer\MSID878.tmp
binary
MD5: be48db826145355a2fe27c1fcc3a57ec
SHA256: cda2856aa93fb4bd21885655a64d3d758de8fe065a1d27acecabfb8e0cdd1f95
3040
msiexec.exe
C:\Windows\Installer\MSID907.tmp
––
MD5:  ––
SHA256:  ––
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_WorkHours_1_1060DDAD78F31A43A0CC9DD0715B3820.dat
xml
MD5: 807ef0fc900feb3da82927990083d6e7
SHA256: 4411e7dc978011222764943081500fff0e43cbf7ccd44264bd1ab6306ca68913
3040
msiexec.exe
C:\Windows\Installer\15cdda.ipi
binary
MD5: 0597d5d560faa976c645bc10774a5687
SHA256: abd30ca2e77b419282ce1579d5c765f503eee3bf400e48b326e05be60a7b6bb1
3040
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF013B9F2E567E069F.TMP
––
MD5:  ––
SHA256:  ––
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\EMMAddin_dll[3]
image
MD5: 74f87e31db9ed9b3724ff2e1c4519738
SHA256: 32fe95c72d14ed4b2c4019326c09f6f03d9fbeb88bf207bfba0abf870c5aabfd
3040
msiexec.exe
C:\Windows\Installer\15cdd9.msi
––
MD5:  ––
SHA256:  ––
3540
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
text
MD5: bb91bda0a34ef0773e79e24a33cbc37b
SHA256: e661435df0eac22150fecc1e49a4b302f144f70eced2a099ccce6b09eff18815
3540
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 5a9ab5e915d55f2016a8406d6db46dbd
SHA256: 5bd61dcda5a94b382df39a40550b3086046ba8e6262ecb30903d5b12b3e4d877
3540
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 3909632f791b267fba7403ed1277cd31
SHA256: 10c82a1c8cb3775d67e607fbf239283a3aed23bf8d609c91f707cee75f0299e7
3540
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: cdef72d876bd1f87ab92bddfb56fc8a4
SHA256: f1aa9ca42cac0cce7b32b858dadd788c1f47777baa4339b769ffda8ac59add74
3540
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 4d7139fb491a047e3fbae4107bb6160c
SHA256: ff4909296a4e4158afc521cc744572b96247c650086b617bcf851188fa4d1739
3540
DrvInst.exe
C:\Windows\INF\setupapi.ev1
binary
MD5: 06cdcbbf83f5419b900ada85acaae3bd
SHA256: fdd0a1ebd1e7d135a20106416fdf4b6bbf5242187fc85cf2dce0afeda18ce0a9
3540
DrvInst.exe
C:\Windows\INF\setupapi.ev3
binary
MD5: 627fe7edb33ba7093fea154ede035a2f
SHA256: 6c3c45c455dbd7e39e89a855fe508f236982bcc8243add10b4fda5781a159c53
3040
msiexec.exe
C:\System Volume Information\SPP\metadata-2
––
MD5:  ––
SHA256:  ––
3040
msiexec.exe
C:\System Volume Information\SPP\snapshot-2
binary
MD5: cb2bbfd7a56d0621cf40028d5a94ee49
SHA256: f7c91b7347ca6b17b5f20516c59ef0a94ea4dd6885e174867577284e951c75d9
3040
msiexec.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{edc2afea-0656-49f8-a588-8a625565b782}_OnDiskSnapshotProp
binary
MD5: cb2bbfd7a56d0621cf40028d5a94ee49
SHA256: f7c91b7347ca6b17b5f20516c59ef0a94ea4dd6885e174867577284e951c75d9
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\EMMAddin_dll[2]
image
MD5: 9dd551bd12ea5c661c11fdde2b52dab1
SHA256: 50f76974434ed1eed6dc594b3f9823282afbadebe137f42cf5d4a17eafaebb69
3584
EMMSetup.exe
C:\Users\admin\AppData\Local\Temp\MSI5E75.tmp
––
MD5:  ––
SHA256:  ––
3584
EMMSetup.exe
C:\ProgramData\DS Development\SetupCache\EMMSetup.msi
––
MD5:  ––
SHA256:  ––
2724
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\EMMAddin_dll[3]
image
MD5: d5a816ded758c84593cbd3e1a9d88a01
SHA256: cb89e9ccc4ab3064031a19e75ce50c18121224e2dab917f41677b34d43c85db1

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2724 OUTLOOK.EXE GET –– 64.4.26.155:80 http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig US
––
––
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2724 OUTLOOK.EXE 64.4.26.155:80 Microsoft Corporation US whitelisted

DNS requests

Domain IP Reputation
config.messenger.msn.com 64.4.26.155
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.