URL:

https://ow-debug-log-commander.software.informer.com/10.3/

Full analysis: https://app.any.run/tasks/e97cc16b-8761-4443-b9fe-f3db345cf005
Verdict: Malicious activity
Analysis date: December 05, 2024, 15:46:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

663C31DEAEBEDFD4D9CC3A0E81B3ADD6

SHA1:

3D354DB3ADAF18DCCACE354AADB2FFD447185919

SHA256:

96ACBB5EBC788F04AB90D1DE646B01CFABFD86B67758405EC357CB8314D99D18

SSDEEP:

3:N8bI2Hk5UXt9j4ip:2s2Hkm70ip

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to autorun other applications

      • siinst_1.6.tmp (PID: 7048)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • siinst_1.6.tmp (PID: 7048)
    • Process drops legitimate windows executable

      • siinst_1.6.tmp (PID: 7048)
      • tmp5822.tmp (PID: 3416)
    • Executable content was dropped or overwritten

      • tmp5822.tmp (PID: 3416)
      • tmp5822.exe (PID: 7068)
      • siinst_1.6.exe (PID: 7296)
      • siinst_1.6.exe (PID: 7228)
      • siinst_1.6.tmp (PID: 7048)
    • Application launched itself

      • softinfo.exe (PID: 1796)
    • Executes application which crashes

      • softinfo.exe (PID: 7740)
      • softinfo.exe (PID: 4604)
      • softinfo.exe (PID: 3280)
      • softinfo.exe (PID: 3952)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 7868)
    • Reads the computer name

      • identity_helper.exe (PID: 7868)
    • Reads Environment values

      • identity_helper.exe (PID: 7868)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 3812)
      • msedge.exe (PID: 7628)
      • msedge.exe (PID: 6412)
    • Application launched itself

      • msedge.exe (PID: 3812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
241
Monitored processes
94
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs siinst_1.6.exe siinst_1.6.tmp no specs siinst_1.6.exe siinst_1.6.tmp msedge.exe no specs msedge.exe no specs softinfo.exe schtasks.exe no specs conhost.exe no specs softinfo.exe msedge.exe no specs tmp5822.exe tmp5822.tmp msedge.exe no specs softinfo.exe no specs softinfo.exe softinfo.exe no specs softinfo.exe no specs softinfo.exe no specs msedge.exe no specs softinfo.exe no specs softinfo.exe no specs softinfo.exe no specs msedge.exe no specs softinfo.exe msedge.exe no specs msedge.exe no specs werfault.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msedge.exe no specs softinfo.exe msedge.exe no specs werfault.exe no specs msedge.exe no specs msedge.exe no specs softinfo.exe werfault.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs softinfo.exe werfault.exe no specs explorer.exe no specs COpenControlPanel no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs softinfo.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1704C:\WINDOWS\system32\WerFault.exe -u -p 7740 -s 1412C:\Windows\System32\WerFault.exesoftinfo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
1796"C:\Program Files\Software Informer\softinfo.exe"C:\Program Files\Software Informer\softinfo.exe
siinst_1.6.tmp
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Software Informer
Version:
1.6.1417.0
Modules
Images
c:\program files\software informer\softinfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1864"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5408 --field-trial-handle=2284,i,9202807200867148553,13531875390114251214,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
2096C:\WINDOWS\system32\WerFault.exe -u -p 4604 -s 1264C:\Windows\System32\WerFault.exesoftinfo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
2484"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=7480 --field-trial-handle=2284,i,9202807200867148553,13531875390114251214,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
2624"C:\Program Files\Software Informer\softinfo.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-sandbox --user-agent="Mozilla/5.0 (Windows NT 10.0; CEF/3.2272.2035) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 SoftwareInformer/1.6.1417" --enable-chrome-runtime --user-data-dir="C:\Users\admin\AppData\Roaming\Software Informer\WbaCache\CEF" --log-severity=disable --field-trial-handle=6368,i,17757154277613986774,10828599569760629953,262144 --disable-features=EnableHangWatcher --variations-seed-version --enable-logging=handle --log-file=2308 --mojo-platform-channel-handle=6392 /prefetch:8C:\Program Files\Software Informer\softinfo.exesoftinfo.exe
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Software Informer
Version:
1.6.1417.0
2828"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=6184 --field-trial-handle=2284,i,9202807200867148553,13531875390114251214,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
3280"C:\Program Files\Software Informer\softinfo.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-sandbox --user-agent="Mozilla/5.0 (Windows NT 10.0; CEF/3.2272.2035) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 SoftwareInformer/1.6.1417" --enable-chrome-runtime --user-data-dir="C:\Users\admin\AppData\Roaming\Software Informer\WbaCache\CEF" --log-severity=disable --field-trial-handle=6352,i,17757154277613986774,10828599569760629953,262144 --disable-features=EnableHangWatcher --variations-seed-version --enable-logging=handle --log-file=1244 --mojo-platform-channel-handle=6524 /prefetch:8C:\Program Files\Software Informer\softinfo.exe
softinfo.exe
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Software Informer
Exit code:
0
Version:
1.6.1417.0
3416"C:\Users\admin\AppData\Local\Temp\is-2VHMP.tmp\tmp5822.tmp" /SL5="$901E8,93484603,832512,C:\Users\admin\AppData\Local\Temp\tmp5822.exe" /verysilent /dir "C:\Program Files\Software Informer\cef"C:\Users\admin\AppData\Local\Temp\is-2VHMP.tmp\tmp5822.tmp
tmp5822.exe
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2vhmp.tmp\tmp5822.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3436"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7732 --field-trial-handle=2284,i,9202807200867148553,13531875390114251214,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
20 425
Read events
20 318
Write events
98
Delete events
9

Modification events

(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3812) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
4CE4D2141E872F00
(PID) Process:(3812) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
8591DE141E872F00
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328474
Operation:writeName:WindowTabManagerFileMappingId
Value:
{1F045F20-A17E-4A36-9123-50A0B055F159}
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328474
Operation:writeName:WindowTabManagerFileMappingId
Value:
{7C562361-B57E-45B3-9467-7BDF9DB4BF35}
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328474
Operation:writeName:WindowTabManagerFileMappingId
Value:
{8DA5E642-B8C8-4548-917F-75B48ABA1894}
(PID) Process:(3812) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328474
Operation:writeName:WindowTabManagerFileMappingId
Value:
{5562032E-E6B7-4492-A2DC-66A668B1E98B}
Executable files
162
Suspicious files
912
Text files
400
Unknown types
21

Dropped files

PID
Process
Filename
Type
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF135b42.TMP
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF135b42.TMP
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF135b52.TMP
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF135b52.TMP
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135bdf.TMP
MD5:
SHA256:
3812msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
123
TCP/UDP connections
213
DNS requests
218
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
440
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1488
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1488
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3812
msedge.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
whitelisted
3812
msedge.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDC1EOHqWq4WkcUU7oA%3D%3D
unknown
whitelisted
5240
svchost.exe
GET
206
2.16.10.177:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1733657837&P2=404&P3=2&P4=NI3p9DCkxg591SaZmBnvY5HPwZxSIoCPL6%2fVeuf6K0dP4O0VRoINYf%2fBo6fum1OXkpLGaOxsJpZLLBaI72qTpg%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
2.23.209.161:443
www.bing.com
Akamai International B.V.
GB
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
440
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6412
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6412
msedge.exe
142.250.185.67:443
fonts.gstatic.com
whitelisted
6412
msedge.exe
142.250.184.194:443
pagead2.googlesyndication.com
whitelisted
3812
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 216.58.206.78
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
ow-debug-log-commander.software.informer.com
  • 172.67.43.115
  • 104.22.17.194
  • 104.22.16.194
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
bzib.nelreports.net
  • 2.19.11.120
  • 2.19.11.100
whitelisted

Threats

No threats detected
Process
Message
softinfo.exe
[ETW] Calling onUninstallKeyDeleted
softinfo.exe
[ETW] Calling onUninstallKeyDeleted
softinfo.exe
[ETW] Calling onUninstallKeyDeleted