General Info

File name

vs_community__1081449981.1542694219 (1).exe

Full analysis
https://app.any.run/tasks/3920eeb1-1736-4bf0-8f15-a7d23d4473af
Verdict
Malicious activity
Analysis date
2/11/2019, 12:22:06
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

20702a5967ac4994e6a6429c521ead1a

SHA1

dcaf01287c7564a711631741c7b511a575895968

SHA256

b12c3025d1abac6eebec50fb47b65198985d0ac23af9a2d15d9e504fb8cfe79a

SSDEEP

24576:R2PPEo3XmDMy1GWUmY3JjQAT+jPmkF0sArOI6NQjYFlQv0s2cUCjxM11xoG3j:EHEo3aMy1hxYZUAKjOErIPGKH/994xnT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • vs_installershell.exe (PID: 3432)
  • vs_installershell.exe (PID: 2232)
  • vs_installershell.exe (PID: 2804)
  • vs_installershell.exe (PID: 4060)
  • vs_installershell.exe (PID: 3836)
  • vs_installershell.exe (PID: 3944)
  • vs_installershell.exe (PID: 2764)
  • vs_installershell.exe (PID: 3772)
  • vs_installerservice.exe (PID: 3460)
  • vs_installershell.exe (PID: 3080)
  • vs_setup_bootstrapper.exe (PID: 3208)
Application was dropped or rewritten from another process
  • vs_installer.exe (PID: 2080)
  • vs_installerservice.exe (PID: 3460)
  • vs_installer.windows.exe (PID: 992)
  • vs_setup_bootstrapper.exe (PID: 3208)
Changes settings of System certificates
  • vs_installerservice.exe (PID: 3460)
  • vs_setup_bootstrapper.exe (PID: 3208)
Low-level read access rights to disk partition
  • vs_installerservice.exe (PID: 3460)
Starts CMD.EXE for commands execution
  • vs_installershell.exe (PID: 3080)
Reads Internet Cache Settings
  • vs_installerservice.exe (PID: 3460)
  • vs_setup_bootstrapper.exe (PID: 3208)
Adds / modifies Windows certificates
  • vs_installerservice.exe (PID: 3460)
  • vs_setup_bootstrapper.exe (PID: 3208)
Reads Environment values
  • vs_installerservice.exe (PID: 3460)
  • vs_setup_bootstrapper.exe (PID: 3208)
Creates files in the program directory
  • vs_installerservice.exe (PID: 3460)
  • vs_installer.windows.exe (PID: 992)
  • vs_setup_bootstrapper.exe (PID: 3208)
Application launched itself
  • vs_installershell.exe (PID: 3080)
Reads CPU info
  • vs_setup_bootstrapper.exe (PID: 3208)
Creates a software uninstall entry
  • vs_installer.windows.exe (PID: 992)
Creates files in the user directory
  • vs_installershell.exe (PID: 3080)
Executable content was dropped or overwritten
  • vs_community__1081449981.1542694219 (1).exe (PID: 2940)
  • vs_setup_bootstrapper.exe (PID: 3208)
Checks supported languages
  • vs_setup_bootstrapper.exe (PID: 3208)
Dropped object may contain Bitcoin addresses
  • vs_setup_bootstrapper.exe (PID: 3208)
Reads settings of System Certificates
  • vs_installerservice.exe (PID: 3460)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (64.6%)
.dll
|   Win32 Dynamic Link Library (generic) (15.4%)
.exe
|   Win32 Executable (generic) (10.5%)
.exe
|   Generic Win/DOS Executable (4.6%)
.exe
|   DOS Executable Generic (4.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2017:11:10 19:50:40+01:00
PEType:
PE32
LinkerVersion:
10
CodeSize:
156672
InitializedDataSize:
73216
UninitializedDataSize:
null
EntryPoint:
0x17f8c
OSVersion:
5.1
ImageVersion:
10
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
15.9.28307.344
ProductVersionNumber:
15.9.28307.344
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
Visual Studio Installer
FileVersion:
15.9.28307.344
InternalName:
vs_community.exe
LegalCopyright:
© Microsoft Corporation. All rights reserved.
OriginalFileName:
vs_community.exe
ProductName:
Microsoft Visual Studio
ProductVersion:
15.9.28307.344
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
10-Nov-2017 18:50:40
Detected languages
English - United States
Debug artifacts
E:\Repos\Dev15\VS\out\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb
CompanyName:
Microsoft Corporation
FileDescription:
Visual Studio Installer
FileVersion:
15.9.28307.344
InternalName:
vs_community.exe
LegalCopyright:
© Microsoft Corporation. All rights reserved.
OriginalFilename:
vs_community.exe
ProductName:
Microsoft Visual Studio
ProductVersion:
15.9.28307.344
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
10-Nov-2017 18:50:40
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0002625A 0x00026400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.54132
.data 0x00028000 0x00003800 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.60515
.idata 0x0002C000 0x00000D58 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.32373
.boxld01\xb8 0x0002D000 0x000000B8 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 1.67066
.rsrc 0x0002E000 0x0000CE08 0x0000D000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.85053
.reloc 0x0003B000 0x000029B2 0x00002A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 4.97079
Resources
1

2

3

4

5

6

7

32

107

129

130

Imports
    KERNEL32.dll

    SHLWAPI.dll

    OLEAUT32.dll

    ADVAPI32.dll (delay-loaded)

Exports

Screenshots

Processes

Total processes
106
Monitored processes
41
Malicious processes
21
Suspicious processes
0

Behavior graph

+
drop and start start drop and start vs_community__1081449981.1542694219 (1).exe vs_setup_bootstrapper.exe getmac.exe no specs vs_installer.exe vs_installershell.exe vs_installer.windows.exe no specs vs_installershell.exe no specs cmd.exe no specs cmd.exe no specs fsutil.exe no specs getmac.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs vs_installershell.exe no specs vs_installershell.exe no specs cmd.exe no specs cmd.exe no specs vs_installershell.exe no specs vs_installershell.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs vs_installershell.exe no specs vs_installershell.exe no specs fsutil.exe no specs fsutil.exe no specs wmic.exe no specs wmic.exe no specs cmd.exe no specs vs_installerservice.exe vs_installershell.exe no specs fsutil.exe no specs fsutil.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs fsutil.exe no specs fsutil.exe no specs fsutil.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2940
CMD
"C:\Users\admin\AppData\Local\Temp\vs_community__1081449981.1542694219 (1).exe"
Path
C:\Users\admin\AppData\Local\Temp\vs_community__1081449981.1542694219 (1).exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Visual Studio Installer
Version
15.9.28307.344
Modules
Image
c:\users\admin\appdata\local\temp\vs_community__1081449981.1542694219 (1).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cabinet.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\feclient.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
3208
CMD
"C:\Users\admin\AppData\Local\Temp\891f8157e23d387bf68d\vs_bootstrapper_d15\vs_setup_bootstrapper.exe" --env "_SFX_CAB_EXE_PACKAGE:C:\Users\admin\AppData\Local\Temp\vs_community__1081449981.1542694219 (1).exe _SFX_CAB_EXE_ORIGINALWORKINGDIR:C:\Users\admin\AppData\Local\Temp"
Path
C:\Users\admin\AppData\Local\Temp\891f8157e23d387bf68d\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
Indicators
Parent process
vs_community__1081449981.1542694219 (1).exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Visual Studio Installer
Version
1.18.1049.33485
Modules
Image
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\32512bd09e2231f6eebb15fc17e3ad79\windowsbase.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\416ba33cb980d07643e82c4c45bd5786\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\da36abbea6ef456f432434d4d8d835c1\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\6d09f865a22e2f903b74476769e1b76a\system.xaml.ni.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.setup.engine.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.setup.common.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.telemetry.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.setup.dll
c:\windows\system32\shell32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.utilities.internal.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.remotecontrol.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\newtonsoft.json.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\getmac.exe
c:\windows\system32\rtutils.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\appdata\local\temp\vs_community__1081449981.1542694219 (1).exe
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.numerics\cd7ca8846a122a7e690e11c4611bc902\system.numerics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\c56771a9cfb87e660d60453e232abe27\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml.linq\0261f24b2fd53085823ea90b359d71ee\system.xml.linq.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.setup.download.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\vga.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\01bed42723486eb478a5b3e2557173db\presentationframework.classic.ni.dll
c:\windows\system32\fwpuclnt.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.visualstudio.setup.configuration.interop.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio4b37ff64#\ec80a2cdcf0a749cf0fbcad633b29253\presentationframework-systemxmllinq.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio49d6fefe#\33d15f16d20849f7c46d19b7bc7f4273\presentationframework-systemxml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio84a6349c#\f0a755350257889ec7e0559c4dbfc30a\presentationframework-systemcore.ni.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\msctfui.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\uiautomationtypes\7e77d1835b49fa80598b5c47eaedccfc\uiautomationtypes.ni.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\netutils.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\winmm.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.csharp\dd1e55e4b87101888a94f28ce396f2ea\microsoft.csharp.ni.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\users\admin\appdata\local\temp\891f8157e23d387bf68d\vs_bootstrapper_d15\microsoft.diagnostics.tracing.eventsource.dll
c:\windows\microsoft.net\assembly\gac_msil\system.runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.runtime.dll
c:\windows\microsoft.net\assembly\gac_msil\system.reflection\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.reflection.dll
c:\windows\microsoft.net\assembly\gac_msil\system.text.encoding\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.text.encoding.dll
c:\windows\microsoft.net\assembly\gac_msil\system.reflection.extensions\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.reflection.extensions.dll
c:\windows\microsoft.net\assembly\gac_msil\system.collections\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.collections.dll
c:\windows\microsoft.net\assembly\gac_msil\system.threading\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.threading.dll
c:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrcompression.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.security\11689060f7aa189e220cf9df9a97254e\system.security.ni.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\program files\microsoft visual studio\installer\vs_installer.exe

PID
3408
CMD
"getmac"
Path
C:\Windows\system32\getmac.exe
Indicators
No indicators
Parent process
vs_setup_bootstrapper.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Displays NIC MAC information
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\getmac.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2080
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installer.exe" /finalizeInstall install --in "C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_201902111122363558.json" --locale en-US --activityId "63d4340b-ba12-4c51-b184-8aa5e2265a15" --campaign "1081449981.1542694219" --pipe "1eaaa750-c019-48bc-9758-07de93c7d0ec"
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installer.exe
Indicators
Parent process
vs_setup_bootstrapper.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Visual Studio Installer
Version
1.18.1049
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
3080
CMD
vs_installershell.exe /finalizeInstall install --in "C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_201902111122363558.json" --locale en-US --activityId "63d4340b-ba12-4c51-b184-8aa5e2265a15" --campaign "1081449981.1542694219" --pipe "1eaaa750-c019-48bc-9758-07de93c7d0ec"
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
Parent process
vs_installer.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\native-windows-registry\build\release\windows-registry.node
c:\program files\microsoft visual studio\installer\resources\app\node_modules\enable-wer-windows\build\release\enablewerwin.node
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\resources\app\main\vs_installer.windows.exe
c:\windows\system32\mscms.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\fsutil.exe

PID
992
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\resources\app\main\vs_installer.windows.exe" /finalizeinstall 6F320B93-EE3C-4826-85E0-ADF79F8D4C61 "Visual Studio Installer" "Microsoft Visual Studio Installer" 1.18.1095.110 0 "C:\Program Files\Microsoft Visual Studio\Installer\vs_installer.exe"
Path
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\main\vs_installer.windows.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft.VisualStudio.Installer.Windows
Version
1.18.1049.33485
Modules
Image
c:\program files\microsoft visual studio\installer\resources\app\main\vs_installer.windows.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll

PID
3772
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" --type=renderer --no-sandbox --service-pipe-token=BEA4644A7138659028EB8835EBF350CE --lang=en-US --app-user-model-id=Microsoft.VisualStudio.Installer --app-path="C:\Program Files\Microsoft Visual Studio\Installer\resources\app" --node-integration=true --webview-tag=true --no-sandbox --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=BEA4644A7138659028EB8835EBF350CE --renderer-client-id=3 --mojo-platform-channel-handle=1340 /prefetch:1
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\enable-wer-windows\build\release\enablewerwin.node
c:\program files\microsoft visual studio\installer\resources\app\node_modules\system-colors\build\release\system-colors.node

PID
2948
CMD
C:\Windows\system32\cmd.exe /d /s /c "getmac"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3056
CMD
C:\Windows\system32\cmd.exe /d /s /c "wmic computersystem get domain"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe

PID
3396
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
536
CMD
getmac
Path
C:\Windows\system32\getmac.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Displays NIC MAC information
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\getmac.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2864
CMD
wmic computersystem get domain
Path
C:\Windows\System32\Wbem\WMIC.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
2780
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
3064
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
4060
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
2232
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\devobj.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\vs_installerservice.exe

PID
924
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
2320
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
3432
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
3836
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
4024
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
3584
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
3480
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
2120
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
2804
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
3944
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
2820
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1576
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3912
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
3544
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
1216
CMD
C:\Windows\system32\cmd.exe /s /d /c call "C:\Program Files\Microsoft Visual Studio\Installer\resources\app\node_modules\microsoft-servicehub\launchController.cmd" "C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\microsoft visual studio\installer\vs_installershell.exe

PID
3460
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Hosts\Microsoft.ServiceHub.Host.CLR\vs_installerservice.exe" desktopClr$C94B8CFE-E3FD-4BAF-A941-2866DBB566FE 15009cbe528d97159f680940318d1fb4
Path
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Hosts\Microsoft.ServiceHub.Host.CLR\vs_installerservice.exe
Indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft
Description
ServiceHub.Host.CLR
Version
1.3.23.60376
Modules
Image
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\vs_installerservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\microsoft.servicehub.hostlib.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\streamjsonrpc.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\microsoft.visualstudio.validation.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\newtonsoft.json.dll
c:\windows\system32\psapi.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\hosts\microsoft.servicehub.host.clr\microsoft.visualstudio.threading.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.numerics\cd7ca8846a122a7e690e11c4611bc902\system.numerics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\c56771a9cfb87e660d60453e232abe27\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml.linq\0261f24b2fd53085823ea90b359d71ee\system.xml.linq.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.validation.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.setup.service.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.setup.common.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.setup.engine.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.setup.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.setup.download.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.telemetry.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.remotesettingsproviderservice.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.servicehub.common.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\streamjsonrpc.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\newtonsoft.json.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.remotecontrol.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.utilities.internal.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.diagnostics.tracing.eventsource.dll
c:\program files\microsoft visual studio\installer\resources\app\servicehub\services\microsoft.visualstudio.setup.service\microsoft.visualstudio.threading.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\smdiagnostics\4a2a848ea1fea1a74d5aa2f1c21c5ce8\smdiagnostics.ni.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.servd1dec626#\52e9ac689c75dd011f0f7e827551e985\system.servicemodel.internals.ni.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\propsys.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\microsoft visual studio\installer\vs_installer.exe
c:\windows\system32\gpapi.dll
c:\windows\microsoft.net\assembly\gac_msil\system.runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.runtime.dll
c:\windows\microsoft.net\assembly\gac_msil\system.reflection\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.reflection.dll
c:\windows\microsoft.net\assembly\gac_msil\system.text.encoding\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.text.encoding.dll
c:\windows\microsoft.net\assembly\gac_msil\system.reflection.extensions\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.reflection.extensions.dll
c:\windows\microsoft.net\assembly\gac_msil\system.collections\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.collections.dll
c:\windows\microsoft.net\assembly\gac_msil\system.threading\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.threading.dll
c:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.security\11689060f7aa189e220cf9df9a97254e\system.security.ni.dll
c:\windows\system32\msi.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrcompression.dll

PID
2764
CMD
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe" ./node_modules/microsoft-servicehub/host/HubController.js 10e11454226e8be949e8077b8ef48da5b9ecb09de9cf662fde4ff6cdadddcf62
Path
C:\Program Files\Microsoft Visual Studio\Installer\vs_installershell.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
21
Version:
Company
Microsoft Corporation
Description
Microsoft Visual Studio Installer
Version
2.0.0
Modules
Image
c:\program files\microsoft visual studio\installer\vs_installershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft visual studio\installer\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft visual studio\installer\msvcp140.dll
c:\program files\microsoft visual studio\installer\vcruntime140.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\microsoft visual studio\installer\ucrtbase.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l2-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-localization-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-synch-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\microsoft visual studio\installer\api-ms-win-core-file-l1-2-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-string-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-math-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-time-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\microsoft visual studio\installer\api-ms-win-crt-conio-l1-1-0.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft visual studio\installer\ffmpeg.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\program files\microsoft visual studio\installer\resources\app\node_modules\wer-api-windows\build\release\werapiwin.node
c:\windows\system32\wer.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll

PID
2252
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2540
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
4088
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
3780
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
1708
CMD
wmic os get locale
Path
C:\Windows\System32\Wbem\wmic.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\xml\wmi2xml.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\sxs.dll

PID
2456
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3004
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3160
CMD
C:\Windows\System32\fsutil.exe dirty query C:
Path
C:\Windows\System32\fsutil.exe
Indicators
No indicators
Parent process
vs_installershell.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
fsutil.exe
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\fsutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
1383
Read events
1267
Write events
116
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2940
vs_community__1081449981.1542694219 (1).exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2940
vs_community__1081449981.1542694219 (1).exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
EnableFileTracing
0
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
EnableConsoleTracing
0
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
FileTracingMask
4294901760
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
ConsoleTracingMask
4294901760
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
MaxFileSize
1048576
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
FileDirectory
%windir%\tracing
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASMANCS
EnableFileTracing
0
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASMANCS
EnableConsoleTracing
0
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASMANCS
FileTracingMask
4294901760
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASMANCS
ConsoleTracingMask
4294901760
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASMANCS
MaxFileSize
1048576
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_setup_bootstrapper_RASMANCS
FileDirectory
%windir%\tracing
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_201902111122363558.json
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
vs_setup_bootstrapper.exe
3208
vs_setup_bootstrapper.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Blob
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000053000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C00F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF01D0000000100000010000000918AD43A9475F78BB5243DE886D8103C030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE47419000000010000001000000068CB42B035EA773E52EF50ECF50EC52909000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030862000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB20000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\Telemetry\PersistentPropertyBag
mac.address
s:2bd74431091d2dd6022fe25665232225db1c71dff90df39a2b572f959b8deea2
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\Telemetry\PersistentPropertyBag\c57a9efce9b74de382d905a89852db71
VS.Core.HardwareId
s:BD6BF059BE6A852C1008961C54FFF116722606BAF338B0CEC08C5D07FB4B1FCC
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
__comment
True enables feature, False turns feature off
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
RecommendSel
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\SortWklds*
0:SortWklds:Flight.VSWSortWklds
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\SortWklds*
1:SortWklds
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\RecWklds*
0:RecWklds:Flight.VSWRecWklds
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\RecWklds*
1:RecWklds
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
Surveys
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\ShowBitrate*
0:ShowBitrate:Flight.VSWShowBitrate
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\ShowBitrate*
1:ShowBitrate
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\CloudFirstDesc*
0:CloudFirstDesc:Flight.VSWCloudFirstDesc
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\CloudFirstDesc*
1:CloudFirstDesc
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\CloudNativeDesc*
0:CloudNativeDesc:Flight.VSWCloudNativeDesc
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\CloudNativeDesc*
1:CloudNativeDesc
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
InstallationOptionsPageKS
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\ProblemsDlgRetry*
0:ProblemsDlgRetry:Flight.VSWProblemsDlgRetry
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\ProblemsDlgRetry*
1:ProblemsDlgRetry
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\CommonError*
0:CommonError:IsInternal
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features\CommonError*
1:CommonError
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
DownloadThenUpdate
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
BackgroundDownload
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Features
EnableVSIXV1Block
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Variables
BatteryPercentage
0.7
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Variables
DiskSpacePercentageRemaining
0.0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json\238\Installer\Variables
DiskSpaceSizeRemaining
10
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json
FileVersion
238
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\RemoteSettings\RemoteSettings_Installer.json
SettingsVersion
2
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\3CAF9BA2DB5570CAF76942FF99101B993888E257
Blob
0300000001000000140000003CAF9BA2DB5570CAF76942FF99101B993888E257140000000100000014000000CB11E8CAD2B4165801C9372E331616B94C9A0A1F040000000100000010000000839A3145057932596326B0129D44A1D50F000000010000001400000027543A3F7612DE2261C7228321722402F63A07DE190000000100000010000000FE24F2EA00130A30CAFACB26837E8A28180000000100000010000000983B132635B7E91DEEF54A6780C092692000000001000000C0050000308205BC308203A4A003020102020A6133261A000000000031300D06092A864886F70D0101050500305F31133011060A0992268993F22C6401191603636F6D31193017060A0992268993F22C64011916096D6963726F736F6674312D302B060355040313244D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479301E170D3130303833313232313933325A170D3230303833313232323933325A3079310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E312330210603550403131A4D6963726F736F667420436F6465205369676E696E672050434130820122300D06092A864886F70D01010105000382010F003082010A0282010100B272595C193064BF1D9A602020429976536C3E1BD66FCCCBF1EA6BFE971610E0DF3A74831AB72FA032ECFFDEC2424E23D57200DB35570A89CAAE2049F4F068AC4D4B8DA5BD794B719B4707DAFD25DF9D7588CFAA73447FD781DBF3BDF236A4C95C45DCAFAD3DE02868971AA7A5727356F11794E4FD359472A0D6765F1E774583853816D0735B05BA67528DA5B2692FDA190BFE927429E2762F54DD143059F8D28D62FDCBC95F463150B92713E44030CF7229102822C7374E3DA0323D90CDA13806855C4E5682282A0532B74BD74F63E7D22D62F1453DE7AC0800F646A19ED15B8C2653E87AAA4AF246CF373C389EB4775CA5179E8DCB118F563CC1AC095F03D30203010001A382015E3082015A300F0603551D130101FF040530030101FF301D0603551D0E04160414CB11E8CAD2B4165801C9372E331616B94C9A0A1F300B0603551D0F040403020186301206092B060104018237150104050203010001302306092B060104018237150204160414FDD1314ED3268A95E198603BA8316FA63CBCD82D301906092B0601040182371402040C1E0A00530075006200430041301F0603551D230418301680140EAC826040562797E52513FC2AE10A539559E4A430500603551D1F044930473045A043A041863F687474703A2F2F63726C2E6D6963726F736F66742E636F6D2F706B692F63726C2F70726F64756374732F6D6963726F736F6674726F6F74636572742E63726C305406082B0601050507010104483046304406082B060105050730028638687474703A2F2F7777772E6D6963726F736F66742E636F6D2F706B692F63657274732F4D6963726F736F6674526F6F74436572742E637274300D06092A864886F70D0101050500038202010059393E7F2646AFEB6F40B132B56AEB0E2F6EA849F7EB5F75ED4C3B2DD743AD0BFECBE92D31A323CC7C509880215DAC3D2F4CBAA2A8569CE370BBB8B4F879B54972F73EEA417FCAE10C1769CBA59C202DFA0B50C456CD2DE34AD2BC70E7A80DA203A556E0B88A4B57F295429CF1F3EFEEE3861F343CB8569AF05323852AA4821C93E294071DF2E24EF88CA1CAE813A5914EC81BD28F72952A716D9B1AF81CF053D667CC22FF5C1DCDA28CBD27B279635644A251CDF9E9A35856DD9B0245442F5FF4DAAED482326EFCA49513E4EB69E7A9A22CBEC82B100E658E99DBF5A2FA122609653894F17A1F4ABBD1E156E8D07896185CC935165FDD931D498E2DBEAD34441CEE10151A005DDD355B21CE98C709EE850E8C4F6D0E134E3D7C29489C72D1F36CCAC1EC70A35792577D948DA01B48035AF7CFA3670A74A536ED2D2F17C8E6723712F46FB13C6782F952B28D3316651E0E8ADD10DE64F46FCE46D4D317E979C404B4D3FB2CDF1F8A9EAC0AFB132740ADE4F9E1A97F46BB0760476560404EB042EC4EEDB37679D80A34096D1C80311FE20E54DDE5A1FBE54710AD6498FF50162E7CBF05217AE295412769C3938F95C98DD89B21AE0D5C9CF0A2AE8668830C6A2DBB766B001D96ADF2167BF6168324B988CF6AA847312F9ADCE3713DD7007E6247D1CE88C9B818FA0E728DC1A33DAF02406AFF699B96E210A810B4375008D6C33D
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3208
vs_setup_bootstrapper.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSCommon\15.0\SQM
OptIn
1
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\ABExp\vs-xsetup\1.18.1095.110
EnabledFlights
tn-nps-15b
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\ABExp
ShippedFlights
lazytoolboxinit
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\ABExp
DisabledFlights
testflight
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\Telemetry\PersistentPropertyBag\vs_setup_bootstrapper
VS.TelemetryApi.ChannelsDisposeLatency
527
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\Telemetry\PersistentPropertyBag\vs_setup_bootstrapper
VS.TelemetryApi.DroppedEventsDuringDisposing
0
3208
vs_setup_bootstrapper.exe
write
HKEY_CURRENT_USER\Software\Microsoft\VisualStudio\Telemetry\PersistentPropertyBag\vs_setup_bootstrapper
VS.TelemetryApi.TotalDisposeLatency
592
2080
vs_installer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
DisplayIcon
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installer.exe"
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
DisplayName
Microsoft Visual Studio Installer
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
DisplayVersion
1.18.1095.110
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
EstimatedSize
0
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
InstallLocation
"C:\Program Files\Microsoft Visual Studio\Installer"
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
InstallDate
20190211
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
ModifyPath
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installer.exe"
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
NoRepair
1
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
Publisher
Microsoft Corporation
992
vs_installer.windows.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}
UninstallString
"C:\Program Files\Microsoft Visual Studio\Installer\vs_installer.exe" /uninstall
3460
vs_installerservice.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3460
vs_installerservice.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASAPI32
EnableFileTracing
0
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASAPI32
EnableConsoleTracing
0
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASAPI32
FileTracingMask
4294901760
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASAPI32
ConsoleTracingMask
4294901760
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASAPI32
MaxFileSize
1048576
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASAPI32
FileDirectory
%windir%\tracing
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASMANCS
EnableFileTracing
0
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASMANCS
EnableConsoleTracing
0
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASMANCS
FileTracingMask
4294901760
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASMANCS
ConsoleTracingMask
4294901760
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASMANCS
MaxFileSize
1048576
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vs_installerservice_RASMANCS
FileDirectory
%windir%\tracing
3460
vs_installerservice.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3460
vs_installerservice.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5
Blob
040000000100000010000000A266BB7DCC38A562631361BBF61DD11B0F000000010000002000000008FBA831C08544208F5208686B991CA1B2CFC510E7301784DDF1EB5BF03932390B00000001000000540000004D006900630072006F0073006F0066007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900200032003000310030000000620000000100000020000000DF545BF919A2439C36983B54CDFC903DFA4F37D3996D8D84B4C31EEC6F3C163E140000000100000014000000D5F656CB8FE8A25C6268D13D94905BD7CE9A18C41D000000010000001000000083D006C6D15405E6CE2847A90A3F3EC969000000010000000E000000300C060A2B0601040182373C03020300000001000000140000003B1EFD3A66EA28B16697394703A72CA340A05BD51900000001000000100000003C70FAEA25600CE3B2CC5F0B222ED6292000000001000000F1050000308205ED308203D5A003020102021028CC3A25BFBA44AC449A9B586B4339AA300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303130301E170D3130303632333231353732345A170D3335303632333232303430315A308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479203230313030820222300D06092A864886F70D01010105000382020F003082020A0282020100B9089E28E4E4EC064E5068B341C57BEBAEB68EAF81BA22441F6534694CBE704017F2167BE279FD86ED0D39F41BA8AD92901ECB3D768F5AD9B591102E3C058D8A6D2454E71FED56AD83B4509C15A51774885920FC08C58476D368D46F2878CE5CB8F3509044FFE3635FBEA19A2C961504D607FE1E8421E0423111C4283694CF50A4629EC9D6AB7100B25B0CE696D40A2496F5FFC6D5B71BD7CBB72162AF12DCA15D37E31AFB1A4698C09BC0E7631F2A0893027E1E6A8EF29F1889E42285A2B1845740FFF50ED86F9CEDE2453101CD17E97FB08145E3AA214026A172AAA74F3C01057EEE8358B15E06639962917882B70D930C246AB41BDB27EC5F95043F934A30F59718B3A7F919A793331D01C8DB22525CD725C946F9A2FB875943BE9B62B18D2D86441A46AC78617E3009FAAE89C4412A2266039139459CC78B0CA8CA0D2FFB52EA0CF76333239DFEB01FAD67D6A75003C6047063B52CB1865A43B7FBAEF96E296E21214126068CC9C3EEB0C28593A1B985D9E6326C4B4C3FD65DA3E5B59D77C39CC055B77400E3B838AB839750E19A42241DC6C0A330D11A5AC85234F773F1C7181F33AD7AECCB4160F3239420C24845AC5C51C62E80C2E27715BD8587ED369D9691EE00B5A370EC9FE38D80688376BAAF5D70522216E266FBBAB3C5C2F73E2F77A6CADEC1A6C6484CC3375123D327D7B84E7096F0A14476AF78CF9AE166130203010001A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E04160414D5F656CB8FE8A25C6268D13D94905BD7CE9A18C4301006092B06010401823715010403020100300D06092A864886F70D01010B05000382020100ACA5968CBFBBAEA6F6D7718743315688FD1C32715B35B7D4F091F2AF37E214F1F30226053E16147F14BAB84FFB89B2B2E7D409CC6DB95B3B64657066B7F2B15ADF1A02F3F551B8676D79F3BF567BE484B92B1E9B409C2634F947189869D81CD7B6D1BF8F61C267C4B5EF60438E101B3649E420CAADA7C1B1276509F8CDF55B2AD08433F3EF1FF2F59C0B589337A075A0DE72DE6C752A6622F58C0630569F40B930AA40771582D78BECC0D3B2BD83C5770C1EAEAF1953A04D79719F0FAF30CE67F9D62CCC22417A07F2974218CE59791055DE6F10E4B8DA836640160968235B972E269A02BB578CC5B8BA69623280899EA1FDC0927C7B2B3319842A63C5006862FA9F478D997A453AA7E9EDEE6942B5F3819B4756107BFC7036841873EAEFF9974D9E3323DD260BBA2AB73F44DC8327FFBD61592B11B7CA4FDBC58B0C1C31AE32F8F8B942F77FDC619A76B15A04E1113D6645B71871BEC92485D6F3D4BA41345D122D25B98DA613486D4BB0077D99930961817457268AAB69E3E4D9C788CC24D8EC52245C1EBC9114E296DEEB0ADA9EDD5FB35BDBD482ECC620508725403AFBC7EECDFE33E56EC3840955032539C0E9355D6531A8F6BFA009CD29C7B336322EDC95F383C15ACF8B8DF6EAB321F8A4ED1E310EB64C11AB600BA412232217A3366482910412E0AB6F1ECB500561B440FF598671D1D533697CA9738A38D7640CF169

Files activity

Executable files
638
Suspicious files
75
Text files
1032
Unknown types
31

Dropped files

PID
Process
Filename
Type
2940
vs_community__1081449981.1542694219 (1).exe
C:\Users\admin\AppData\Local\Temp\891f8157e23d387bf68d\vs_bootstrapper_d15\Microsoft.Diagnostics.Tracing.EventSource.dll
executable
MD5: d088a9cf359b07336e43b5ee7489bdab
SHA256: c4d2b78f633953da790c69dbc72d62b54f258c630a88f7bdfbc4aa600ee362b2
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 849e048d630041d237604e813f626f17
SHA256: 185d94759327f70d7e8390b0ed18dbbcbdf02dda159a62a1317a5a7bf4fbfd63
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.Service.dll
executable
MD5: 8e2b3f0d646d49558e289b2f4c069beb
SHA256: 4c5af4f52d20dd7cdddb34bff64aa912021b4fcd889a0f445afce89758330d38
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: bafa511cf05f04c41b99e870be75e91c
SHA256: 567e7e53d7f503bb2ff9f2c366612e2c1d429c2cb39d93626aedb98510752be6
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.Operations.dll
executable
MD5: ebd6956401261467c3798866c3998c94
SHA256: 4c2233a1a52faf2b9c8bdee78573ad5c399767363982474ff0c2e5719fbdf34b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Telemetry.dll
executable
MD5: 5f134280b941093b30029dd80fe2417f
SHA256: e14adf0dee2d809d26570993bc851bb77a8e81c331227a82fdf25512adbec065
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.MSBuildTasks.dll
executable
MD5: fddc1801f63a5962e33671d78bcd65ba
SHA256: fb63269bc11271a9efcaa4066e66ceb8303050c39d0c7104860e46bfba0bd5fe
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 79d89edd8fd5a9f1b0b737ae6836064d
SHA256: 44b7f592f92ead3a4e1e8cb47bec1aa2451d0d46b4cc76a9260de07f157366da
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.Engine.dll
executable
MD5: b57a1d784c57cf86547ee28f03682fb4
SHA256: e7309158e5f9c51378d93d751dfdfd4eb36465f96f1485149a9839add32c2cc0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 7cfb085c856e04d915c491ab316e07a2
SHA256: 19000246638e6b7133a7db1699616585e0bce80fe9f0a8788bb8ea9b69758a0a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.Download.dll
executable
MD5: d7810249417ed434aa42a84c77d36c46
SHA256: ab504a5634657e4f6075f62da131999b3dec81fe0f8e169577e701b2d2fea055
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: f853f5a9e271a6233066c7c767a37990
SHA256: 49b360eba3e2a7210207f5193fa9224972736547d3e6d5405f3cd25ce1c77a2e
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: e45c9833ca35e3376df8eaf7fff10ac2
SHA256: 493973bb87e6975a4579c93654371c774ddf5e58243b1f82dc06c5d1dc7d6989
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Threading.dll
executable
MD5: 5b2b9a7b209892196f0e8b04f4eaf4d8
SHA256: 3efe30e329d0fbe1de9b61261f301318a3f1d5fddca998ea12174175569b30cb
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.dll
executable
MD5: 4191f3e20afed8692de54f64549e696b
SHA256: f24f0859cd75b9475508475751ac02e9e41dfed87587725e5c13f34bbf5258ec
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: 0479f316d89ab7745812d524d0c09878
SHA256: 44edc0a8fadbfc6f6a2e077101fe35c7d029f5d3498e052dbc3b0f6c71726925
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 2a68927d197e705816f24ca8a393c628
SHA256: 2a70f61b66348fc86a6a60cf40c96f4d8a7f903a0501891fa4c459e519308a79
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Utilities.Internal.dll
executable
MD5: 6b0bf2bb88d9b0add1bc7990a779558b
SHA256: 27e2f03713b0311c98ae2cce3a44bacba83389265cf8178ac6543b80bb9c51f9
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Setup.Common.dll
executable
MD5: 60af5b8750a3e33cb2d92a702bd72b0b
SHA256: a210ea79feb426c73601ce3a801b6dad17d149d6b0b956f5df2f48aadff3dd6b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\VSIXInstaller.resources.dll
executable
MD5: 7fb5bee450f7cafbea64a8c6558b43ad
SHA256: cf5389db05cbde0435d00269ed2e980a49996b3886e246af7be07a3c5af54203
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: c31a7bb2baf96575510e9f48c3df7ca9
SHA256: 75c710691aaa05ab9e955488ce00123f37baff081ed624824b559ffbaed3ac03
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.Validation.dll
executable
MD5: f2b0fd438161082af290e764559a0c31
SHA256: 3f6250900585a3ed8f6bc0b65ca49db303ae9fbe63adbf687928c67e501fd264
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.ServiceHub.Common.dll
executable
MD5: 8d694f6cf682d2baaeafda59ab67f20f
SHA256: 8179819e9cf34d561146791ffab70c8edd1154e86947e1434485209be91897a4
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\StreamJsonRpc.resources.dll
executable
MD5: 71cf00a156e32d3f5d70a9f3c5a6d69c
SHA256: 8b3d2a4db7e5d819e580796e755b142908953b8e7be5f206a5e502490bea0a45
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 6cd8d9d869f03d856321beb4d056e633
SHA256: 706f418e3f7b99a0dc8b8056d3402b681405c0f2425444853ad82ddf7e6571a8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Newtonsoft.Json.dll
executable
MD5: c53737821b861d454d5248034c3c097c
SHA256: 575e30f98e4ea42c9e516edc8bbb29ad8b50b173a3e6b36b5ba39e133cce9406
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.RemoteSettingsProviderService.dll
executable
MD5: 1b9c1d57546dfe3381479a162f2db7f6
SHA256: 19d036f63db6e4cd81ea85032210a1f81869561181bcd4b4e4d6aef3aea57f31
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: dbc1fe33d6c350aa8a8aa28a9ed11618
SHA256: 29ac0c8f6700d94bc95abb191d7b5b465261db19d5d9e12f6ede140b4a2982e3
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\StreamJsonRpc.resources.dll
executable
MD5: aa980ff47ac878b22fd4394aeda54072
SHA256: 39064c29524fe2dcd57ea8920dab9a8607bc8666321f4341a2320926b4a2898b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 1d0bf1f397f39a56db95891acf0d328f
SHA256: 0993bc173904ec77752256fc6640265fc2e958247b0dde4443cdbdba4a0133fa
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.VisualStudio.RemoteControl.dll
executable
MD5: 31c005b43b187c7ade8b9644da122281
SHA256: 5cee339c096ffabea6e1ec6fbba4db0bdd0a981d40d26dc07ea4f7be7b0f2df9
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: bdf10a7476c4f1bfdd9c1c1d78149aa5
SHA256: 151be9bdc61f805fb05f58a7f2663ed22b7cdb991a7117e74e4ead3cf52d0e71
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\fr\VSIXInstaller.resources.dll
executable
MD5: f26e08a2917565876a1d3a52699f1b55
SHA256: 3d5909e75909f1ea23f646026a2071d6253371390b24544af4609bc304cece3b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 9eb085408aa2e88b2f5906535ef0ff23
SHA256: 21d0f609a02fa59fe686daa171d0168b3b9ad205f23b856c5268ad4769c55772
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Microsoft.Diagnostics.Tracing.EventSource.dll
executable
MD5: d088a9cf359b07336e43b5ee7489bdab
SHA256: c4d2b78f633953da790c69dbc72d62b54f258c630a88f7bdfbc4aa600ee362b2
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 74a6dc3d884e5574c2ce2c800c258a76
SHA256: cb1590c2701af0f0f103cfa5848a00f1da482a78df808fc765170e9a3b4ae5ec
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\handle.exe
executable
MD5: 8f06641dc82a45c4c563747ecbd44150
SHA256: e2d9a1d6103d45bb93d0a2d9c1549c143aaf656daeaa58171da56649bf7b69a0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 10676b49173c66548206592edb5956e6
SHA256: d698c22e8691ec690321b9a97ca26020fd0660b8ee6a002ee138576c92956097
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\StreamJsonRpc.resources.dll
executable
MD5: a8681936c80d581bcafc436da1789adf
SHA256: 22dc7e35eafa081982ef806c133bd01d2de9b9a6cd499ff808eac9413cb0d59a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 44ce549ad18e61b8217f163c3ed42c3b
SHA256: db9460d1034ef66dd3ca2ef6ab2ac8a5ef999a940c5ddd6c91e4fee3911a75e8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: 6b2ed360b251b2fbf1a274513a471219
SHA256: 940fe85f6ab8701641e7121d78ea0aed176b7dce09ed9cd3efe4093171a6cad1
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: c81733b63175ccc05c1a7bb5aac17539
SHA256: 028165a00511e5adc6939fcf72c95c0b54af3809274921a08f9dcbdfa5fcf638
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Setup.resources.dll
executable
MD5: 8363bea9a40fa2a6fde12b4cc9b91a2a
SHA256: 1fa8d738a0afa8c0ae6c4259373738ecce83ff60ab895e0c40cec28ab896ca32
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 83ab6edcbc4387fe5b0465fdc2f28aba
SHA256: 088b393f5e2a2120d6435fbfbcd03c5b08fb027d2e310b9154f971b5efd2115b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: acc3563ce28be9c1f3b882826da06e70
SHA256: 5e0ba409421aebccc58fc38504e825f89352ba82c87016ff3edd6b07e704d3c6
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: f24c3c1f2b24cc9e3c742ad4eda94b16
SHA256: 78d3812f509253f7560e53935b12d132ec775bd3f28459fc457066d09e3ba5c4
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 613a5bb344f9ea8510dd1a293f425ea0
SHA256: 108faf266ccf20faa4eba1f78c0756f3491ca9c8a4e80e2d332204026435ab69
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 0ec1b7f16d3a36cdec445947e4d18a12
SHA256: aaa412ab06c7fe5927693c18c39f3e1d114ebffa6525a48ed876b9b3980011fb
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: c291da41e0017084f48d7b55f54638c6
SHA256: be588c9a08d780426f57698b5560f8b82b860c803fe54d015a7af79e7ccb1ff8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: bf8cd95a9a30087d20b1c13c4d547348
SHA256: 8937ec3d8cbe8a6dcf6dab8c33bd81437fac127a3034ac35fa091ff0c33aceae
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: c90fb16fab6040cbdac6d4389230a383
SHA256: f050e1e3d241613d8fc766523f76dd11825e519d9926573908914258937e5604
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 702ece2b30dfa79451a21f00c16affa5
SHA256: b977be2805565c9aa48f4fcd27b934c5ed68ff58dd5d966d7d1f449a1fc9ce96
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: d4e615b28983df92c148fc1a44069215
SHA256: 6f21425d4eb257171e3e9eec219f3fca03a1b9e2bc8761b62e606877d7b26138
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 714b23e4673fcfca23b3d1343e66e7ba
SHA256: c91a91e410594ab4fe5bd432d0e4225518b2d5ffa08b8da08a6e13c989ec8111
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 1272b6266df9b1d8e315dc427929c047
SHA256: 682a192d5e6e5f24c38e63006428752e4257fd62b745766629e4455465ac4520
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 6f563c594b6de190ce2e9d71a7c81a59
SHA256: 932d3907188826953391af22a6744a0d06de6df97d079bee8c81bcc3d0a7e0c5
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 4e7a5c67551c7eb6698fe86c8d8c06b4
SHA256: 959060b8fc4bfd29375ee4302bc43a9db3789c495548ac0a5d0737d19aead1b8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: d18e964827ee502fa5210cffe8691914
SHA256: 2107fee7ce453f3040b1d810207dd02cb3e1e617c3f92047723542e72e4bd512
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 6e817599ffdcd3bb5daa7488222a0441
SHA256: 249dc170bfb82bbcd0bb782778f8913d0f1640fcbc41457501b6c65fbdb02b3c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: be4e86f5a766d73626ef0c2431d91f27
SHA256: 4d045b464d5567f32df93a3e38d88212945e1f4e8752c65d70c08bbea420d1d7
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 304bdf518ecb719bb29dfbcb7083d147
SHA256: 08dd2a5ddfc54cf521b8077b1e176b22b9f8fed61bc2855c71952988f847360c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: dbde3a6f4a30636bad3f72c4bbdb9911
SHA256: 0140242c4ac202157f413dde9f5b0e6f83e1dd1ff3022e8f346a81a8083e04be
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 5b5e95f0a6ba3aa874608fae8b7a033c
SHA256: fe287b60813a257cf7a9678a10546c3ff6053aa82d768288d86a2edde256268d
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: fa04d8f97e60e3f5bcd03679eb5c414b
SHA256: cee09a71e2b3d77e86292615dc7c81bb524923ea5402502949a16d497b796e63
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 1362f98727f543a3e76e0b37d3c9f240
SHA256: ebb469de49ed700d98cedb03a3a1dd9c8d56918a9576150ed8df4ad2e0564673
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\Setup.resources.dll
executable
MD5: 654bbc8544886a86b0770ad7dc6bf668
SHA256: 2621cc0e28e895915dd61a2edeb67477d1b7ec9c7ea7ce9cdec96a22033741cd
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 5a8e4fec0c121927ec09b6eff39d547f
SHA256: 610c429f3c280eded4183f3887878f73d953c8c087cfabf8ce8070a3b77a786b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\es\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: 6fa3a0634921828b1921ca9e4a29dbe1
SHA256: 4efbbf7cf970d284fc862a8b4c097192662cf837dc3c9d9819aba2def2f2e612
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 93bb38a0e3fc30321bdad421565505e6
SHA256: 03e61994d525728e01b9593573ee3d4a6ff107aa48ddbbfca2455d5a0c5d0799
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pl\StreamJsonRpc.resources.dll
executable
MD5: a82261413b4707aaabc494ae8501c8b4
SHA256: aa00285a9de0bafde7157a2b239de5d9d5a0894df555bc6754be047d91bd113f
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: e662cc7ed4accc150d2b8d3850cc5d97
SHA256: 08fadae28939f788a0cd93a2ab3faae2301445c6380583307568e0ac611e8b8c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\VSIXInstaller.resources.dll
executable
MD5: 5b13342bf39ae302977b8d3db1b4dfb4
SHA256: ef89a3393d40f3e559caabd76e7f02c179277e9fcd64bb0c362f2541899582d7
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: ef5467f1cd85f39edd9276830dc3c0be
SHA256: 2a9212a7f45bc8a92af145ef3d212978ccea787606eb96a97fb3dd364b986c78
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 4b981127b7a1c58472d9068df4fa4205
SHA256: 7e9360ed53ea52683f1ea557e2f8f25e3a00b7cd4fa48d3dd0fe8e4c11c2b7a3
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 2b672a653a3d12f739b500dedc07f576
SHA256: 04c432d4bc6026d1115130841ecf3718e0ed63b40cfd12ad06aa055dca9dd8e7
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\StreamJsonRpc.resources.dll
executable
MD5: f9b9d36cd7ac63480ce63688b6cf940d
SHA256: 546d7c181f36006398b55bddff04dec254b796f27a9bbc1dee23646491913436
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 82b8f63cfb3627716bab73bcaab00643
SHA256: 5d3038bf112f6c99f496b0c103fbc6ed7aeb0b3c05a1dd8fee0bd58ffe597c32
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 2cc8682452945424e809fa4f1e38ab46
SHA256: 9ee48daf35110356d6e1a127f1edd9ff615dbb0cfa6d3f1060d277f3720f81be
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ko\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 58325473c788e2e02b508f52db1b955b
SHA256: cddcbd316884843479dcae35324c5b91184037066a25d30be691121e31fb0032
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: df1cd3816112960bed874433eb13fbfe
SHA256: 93b7ccead4c186b489f0f1c50ffbb192f97410e279c75e221b440defd0d27999
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 2ea76b913dedaae9bf54faac4a801b6c
SHA256: 03db0d0621c2d6d28725f39e506ae5cf877a8f19054469005e155b3d522e6a0c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 8a6c1c5e34487ecc38c06d2baf1658b4
SHA256: ce4984eb7a09d2e0496c325a2953dc63cb5e021aa1c1cb52244bd3bd052ebe44
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\StreamJsonRpc.resources.dll
executable
MD5: 2272c7be9f6460096341667ed4394d81
SHA256: f364b89ceb35f9843a4eb52d6837334c09bc8b2126a54023e98cfabfd19ba339
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 06851ce956460080507601a1cde68e39
SHA256: f7e978b7517355b7ddb0042683485ebf1fd124a8d73ac227635cc08581c9a8b5
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\StreamJsonRpc.resources.dll
executable
MD5: f828d79bf67435c5dd8576ef8ea18e24
SHA256: 2576691c77734c49b0abdae73f384a855f6c83f28de0596d2b96d5e1142d9174
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: fadff98e0fefd10faf64a2fe4afee550
SHA256: d7be5c64619fc88e03f94c2b60ba1b80f767da714f7f96e6592492e3455def23
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Setup.resources.dll
executable
MD5: 6fae59586f5f3fd9e782c08ce1ff9c0d
SHA256: 092cc9e3e368309b8355afc3770c70ea2da3cdb8191d982da16520ae7d87dbb0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 6fb2040ce02977616424b4d33fcea8ec
SHA256: 6b107e2cd2cdb034ed9ea7c505ee17842b407193d63ecf96e9e8799e850171c0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\it\VSIXInstaller.resources.dll
executable
MD5: 5996933b28dcf27ede8bf52367648c48
SHA256: ffe982ca9c104c0e5189b6900138af4553905e331c1737d6a00ca2e9143addda
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: aee8739699d8d780a56d38199e69f67d
SHA256: 071a7b632073f2a7a4923d5a856d34c8f77b85297b0a0a9b1a1796d923e3cb5f
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 5468ed0c73db290b95a4b817ca8bab47
SHA256: dc04ae3bbe04fa5affb0b830e3af4fd77c03659320110adc76263c86dac50cc5
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 87ab385ecfb22214570a49cfa298201d
SHA256: 6bf1f55684a6945617c52989ce4663e62fc94c943076f0b7b9e802bed2a092f3
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: 8adc075bd213be9b6e9b8b98906aa558
SHA256: 6c3cc1fb86859e0399e90f187b791b4394bec4433431a4d0f9f5517ae1b6f818
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 6ac9b14050de80c26fb33290f035b55d
SHA256: 9e277dca285f7e9e4eb674365d134d88a7a9dc716be900495d8e1b99cabc10e9
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 11ca9b3a6c0e9578251ff3ad7c13acf5
SHA256: 1ea290ccd79f3917f2d48266bf14b27a505a16bb225a312e7452aec493786ff2
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: cb9c47caae9b1f74fec26560d576be66
SHA256: e078fda24f423a8cdd00fd5341bbcd0e3fa19be0f52e2e86153e59a5525bd54c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: 449fca6e48e8ca5f578caa10cef552cc
SHA256: b8f826e75e1534d4280c0e0318534792c89bde4e167bedefc15db1cdb2dfffb4
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 09e2ee2943628a9bbfc261e4e7b201d8
SHA256: 50b642e0282740834312313d17d5658a426a97e7f9c5513b3424a9771e6246ed
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: e90b2373e2dee639df347472dc388f99
SHA256: 4e4facfc4dd5610f282edb24090dff0a3950df2d5599003abf1884d941d39218
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: b44bd4602322e769f83dd9ff4c1e923c
SHA256: d6c09fbda47ceaeab411becf4f3b317b01dde45df566e52e7851e1799c8ed386
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 1810655819f0dbcbadfe3c861e07fb8d
SHA256: 428af4b44e5b7ab8b4fda3c4822f499c2031c3af2088feae69e58dc883fc4536
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 073cc660475e831b3d918015302b9d6a
SHA256: 0af6a7f67e73cd8ff93a6bc4a6a3a8f0919ca249616d5e6ee8f23b46322daadd
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 735e005816976791972ee783109ff952
SHA256: bdb74ac59b5e51d18f0ac0487033611363d5659e30d4c826bbb50eed40af59e1
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: e33569a872f84abf0c8b4a7a90730625
SHA256: 0a715c22c6674d8ff1dfda926e17377ec7748ba68715903a50e60749822498a6
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 24ef7d38d6ebbf9174b677a09fb6c028
SHA256: 84a491ec596a98b1f4616012fa931f7cf8004dad96a35b96dc139a472c489b6a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 4ff781be16ba9c96b300ee4a221b1357
SHA256: 650909d99cf3643d4c31c0ef7415e8d2b62d102d0e8b224ae2b3e1545154f84c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: bb14ff9632ad823ec561054d91bc2225
SHA256: 6bf753f3055dac6d78c6abd5f2a8f18ba33750c056eddce9dfd9a8763eaf6236
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 14617bd7864d0548f119761df55d3ff7
SHA256: 307b878bb4c60e6096f7da22e2f67e42d7c6b81e619680c6ecf7b1c9810de007
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 42ede5cb912be1a10b4eb8b02da08391
SHA256: df0d81a79a577f6de7975d8292e2454c60a37e606c7bd6b351766b4bda9e08ca
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\Setup.resources.dll
executable
MD5: 85b023492fa9f21ba35fc45d15e23790
SHA256: efd9c07d1189cebef2923da08d0d455e69876b6228abc661018cf4d8d0990b1c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: f0acbb34b998fdbbfacf948cff0ff2a6
SHA256: 0cd5301d6f69952618b6423e7565586a49cd2bf92601678aaf83d606b49781ab
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: f1d7184c08a501acef5a4be1f381a673
SHA256: 7f55355af747212a2451b49dd31fba75821ab1fba045789cbb7f2b7da258df22
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: f0acbb34b998fdbbfacf948cff0ff2a6
SHA256: 0cd5301d6f69952618b6423e7565586a49cd2bf92601678aaf83d606b49781ab
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\pt-BR\StreamJsonRpc.resources.dll
executable
MD5: 27fb0d9671caf1feba7272e55db872e0
SHA256: 1e819b8c48cfc81cc3f2fc7e98cc8b58a766ff4691138d1c2ce9be2bb97c7606
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 42ede5cb912be1a10b4eb8b02da08391
SHA256: df0d81a79a577f6de7975d8292e2454c60a37e606c7bd6b351766b4bda9e08ca
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: d6dae6ecdfc7530d8b89039049a0fde6
SHA256: 4e62e662d925262216ab278dc3e91875899dcab9e34f59a86b8db2054a5fdfd4
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: bb14ff9632ad823ec561054d91bc2225
SHA256: 6bf753f3055dac6d78c6abd5f2a8f18ba33750c056eddce9dfd9a8763eaf6236
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 40778ca6d31ea54ef69e0cd423eaed18
SHA256: 38336d492ecbef05a753e45ef8b3bfefd00095474ccfdd17bc2da15d1d7fff59
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 24ef7d38d6ebbf9174b677a09fb6c028
SHA256: 84a491ec596a98b1f4616012fa931f7cf8004dad96a35b96dc139a472c489b6a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\de\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: 6b7ce33b3c70c50768b291d898cf2dfa
SHA256: 3239318b9ea5ae4cffae60faaeb1f944cc77240f54c5e29723719130e6f22f43
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 735e005816976791972ee783109ff952
SHA256: bdb74ac59b5e51d18f0ac0487033611363d5659e30d4c826bbb50eed40af59e1
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: f16b7b73def940d65c313fcfe29b3031
SHA256: b269058f3144b2084d8a0513e383112be43b61d6b67a1ec680a8663a75aaceda
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ja\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 1810655819f0dbcbadfe3c861e07fb8d
SHA256: 428af4b44e5b7ab8b4fda3c4822f499c2031c3af2088feae69e58dc883fc4536
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\VSIXInstaller.resources.dll
executable
MD5: f24310519b24fab917ccad0f73b1f564
SHA256: ebd5ae4eb425551f4534095a1a2a3be942ac02e84af694e049a7ff42c4412584
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 11ca9b3a6c0e9578251ff3ad7c13acf5
SHA256: 1ea290ccd79f3917f2d48266bf14b27a505a16bb225a312e7452aec493786ff2
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: cb899028fa132d89529227b4c0b3f848
SHA256: c882ab8d7b4700a323388c8e1f5e1c21875d944afca488600067fe0918f3d304
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\StreamJsonRpc.resources.dll
executable
MD5: f828d79bf67435c5dd8576ef8ea18e24
SHA256: 2576691c77734c49b0abdae73f384a855f6c83f28de0596d2b96d5e1142d9174
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\StreamJsonRpc.resources.dll
executable
MD5: eb764da9c5479cb436b6c81fc8c0ea7c
SHA256: d4e924039e52c9c6685be5346de74884881cd23100fc597623021035d61fad1e
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: e90b2373e2dee639df347472dc388f99
SHA256: 4e4facfc4dd5610f282edb24090dff0a3950df2d5599003abf1884d941d39218
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 0fd7339afa812fe2f557e09f4e22d653
SHA256: a93954bba13ec80945211e4403464276fd2e9b611fc3a62aa69d50282d7085cc
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Setup.resources.dll
executable
MD5: fb4a1b5dd373ed57ca7d2701d664ed1f
SHA256: 0efd4ee6c0f58a13809a23f0f09ed20aa8bd7ef70050480743be1ddf2dd2d9ae
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: c81127602816d99f0b7bec250dfd31d7
SHA256: 84221dd8c0d2736310577350aa9b86afee120f439e0ab5de446c74432548405a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 5468ed0c73db290b95a4b817ca8bab47
SHA256: dc04ae3bbe04fa5affb0b830e3af4fd77c03659320110adc76263c86dac50cc5
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 9ae6e96c8e3e164aa41244da56771169
SHA256: 72c020dd68bb0acc1298c0e240b5586f874af68d32ba96479a07672749fc82f0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 2ea76b913dedaae9bf54faac4a801b6c
SHA256: 03db0d0621c2d6d28725f39e506ae5cf877a8f19054469005e155b3d522e6a0c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: be31711be44fc70962a3ef1c31a09af0
SHA256: cb42b01125c0cca85a8e8f4edf890c77369df358b4e2474de8d579c8dea7ea56
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\StreamJsonRpc.resources.dll
executable
MD5: 2272c7be9f6460096341667ed4394d81
SHA256: f364b89ceb35f9843a4eb52d6837334c09bc8b2126a54023e98cfabfd19ba339
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: c18a3bee7eae69a0e33d548ab58305ca
SHA256: f934bfdb459c431b3343c4d244bba68272b50ecaca1fb160498d96ecace989a7
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 82b8f63cfb3627716bab73bcaab00643
SHA256: 5d3038bf112f6c99f496b0c103fbc6ed7aeb0b3c05a1dd8fee0bd58ffe597c32
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: c0cfd4bf51a6d887f9c8d564fab99fb5
SHA256: 0787ea02e7f83614dd8eb86676cca46eefcdf0287351fc49c119df4e3da7d309
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ja\VSIXInstaller.resources.dll
executable
MD5: 43dace9ea1d756cf5100df74e5832670
SHA256: b5f724232f9b95ff6fd4ef25cd5f4c20b2117dbe5683136fd149e344514330b1
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 52c4d1f7364421cec5843b0f8ca4acfc
SHA256: b6f8798ffa85ebe6452a352a35d9c9bb09a1e386d49f204f499674f7df9d4383
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: ef5467f1cd85f39edd9276830dc3c0be
SHA256: 2a9212a7f45bc8a92af145ef3d212978ccea787606eb96a97fb3dd364b986c78
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: b012fd4fc7d6d71c0c09226b79d1ee2e
SHA256: e44012447630a87349a887ca295c9fb74c30c76e47a9915d768586cbbb0b5f6f
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: e5079bb45416dadd2a8578ec692ee0c7
SHA256: 5dc59ba979684cffd7817b35774d0d1906a93c582a7d6eb4bc1f58444a8ddc79
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 67d41980962d4e04a8d420bdaba0cdfd
SHA256: 486d1161c3f09ade30199c6e848da2465fa915a1f161422f47407064d9751d0b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 93bb38a0e3fc30321bdad421565505e6
SHA256: 03e61994d525728e01b9593573ee3d4a6ff107aa48ddbbfca2455d5a0c5d0799
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 8090c23b300150ea21e6cb37fcff16b2
SHA256: e7b28d92150acd0757106bd83fbadc6f419787e29fbebf96740a85e8922c604a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: f685551fca6b2c1c3b0a41472144322d
SHA256: c8200c7facccc4f1ce6e7d43ef0e7f17471dfa420a106e859fd3681c49ec0274
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: fd0a0eeb20db415c95798952b0692e82
SHA256: 0da800d3fbc11e0577ba74a18eab2aa16540d54d85ffb0e702353a256af47ef0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 1362f98727f543a3e76e0b37d3c9f240
SHA256: ebb469de49ed700d98cedb03a3a1dd9c8d56918a9576150ed8df4ad2e0564673
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 02ec2b6a157fd2a2beda1e96312e6458
SHA256: 1700391921894e6b03eb94f210dbba30b54142b51bf4f16d5179d0378a8b93cd
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 58325473c788e2e02b508f52db1b955b
SHA256: cddcbd316884843479dcae35324c5b91184037066a25d30be691121e31fb0032
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\Setup.resources.dll
executable
MD5: 01e1e5b7aeba480c5f2ab07c29c218e6
SHA256: 8e5e32e4a3c1dada31435da728baf5a00ba1ca0a3d51a3fe22dbf8bf2c815751
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 304bdf518ecb719bb29dfbcb7083d147
SHA256: 08dd2a5ddfc54cf521b8077b1e176b22b9f8fed61bc2855c71952988f847360c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 15b3eb38308cd57624b5552b518ae56f
SHA256: f8e7856b1bdec61eb9081c1123f30004caf2a14f3d8580197485987378a2228a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 2b672a653a3d12f739b500dedc07f576
SHA256: 04c432d4bc6026d1115130841ecf3718e0ed63b40cfd12ad06aa055dca9dd8e7
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\ru\StreamJsonRpc.resources.dll
executable
MD5: 8a34bb282d0d80f175def7e980d48a3d
SHA256: e5db71eab0fb80efde0f817326ef4463f2fa5606f21f2c41a453460314646172
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 4e7a5c67551c7eb6698fe86c8d8c06b4
SHA256: 959060b8fc4bfd29375ee4302bc43a9db3789c495548ac0a5d0737d19aead1b8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: 8b1e9d80327c909c9a65c4d14cecdfb4
SHA256: cea6e9c937946031166618f26571a9d04ffdda473e13a2bf290b0341ebf44454
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: e662cc7ed4accc150d2b8d3850cc5d97
SHA256: 08fadae28939f788a0cd93a2ab3faae2301445c6380583307568e0ac611e8b8c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\Setup.exe
executable
MD5: aeedb46c35e779d8c9bc2cc41b3d6ff6
SHA256: fdaeb10de360e52ce72e3e8c366934153adafa02cbe7c685ec71481303f2e839
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: d4e615b28983df92c148fc1a44069215
SHA256: 6f21425d4eb257171e3e9eec219f3fca03a1b9e2bc8761b62e606877d7b26138
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: 1fa3df90182db5d4d4fd458bd6950bb7
SHA256: ee63eec15ac43e798ae7959703635c3b9ffb3eb3bc025443b1233ddd321627da
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 5a8e4fec0c121927ec09b6eff39d547f
SHA256: 610c429f3c280eded4183f3887878f73d953c8c087cfabf8ce8070a3b77a786b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\StreamJsonRpc.dll
executable
MD5: 2de027f919107545dac4bb655f4b383b
SHA256: ba94a53f9cb6be3dcb79c7fa4a0bb46493057150e9b884ef447c760a49383208
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\it\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: c291da41e0017084f48d7b55f54638c6
SHA256: be588c9a08d780426f57698b5560f8b82b860c803fe54d015a7af79e7ccb1ff8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.VisualStudio.ExtensionEngine.resources.dll
executable
MD5: ad8c7340ad9237ab3092609de0cb491b
SHA256: 8faa03f1d14fbbbce781d9ddb157371a5e56f60bad1b88725df3ae8c00316a46
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 5b5e95f0a6ba3aa874608fae8b7a033c
SHA256: fe287b60813a257cf7a9678a10546c3ff6053aa82d768288d86a2edde256268d
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\tr\Microsoft.VisualStudio.RemoteSettingsProviderService.resources.dll
executable
MD5: d323f057282b307c8227f35891335894
SHA256: dca1751163a65a5c1e72d64f5efdb54e9cecdd5154ede9b57d73719ff7ad95ec
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\InstallCleanup.exe
executable
MD5: 20b2e59b51bbd400c75b884abdb37021
SHA256: 929a1360dc2ca567af10b5e350feb93c91d99e3bf70ebc92878ccb350d93d87c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\cs\Microsoft.ServiceHub.Client.resources.dll
executable
MD5: 0d101223bc1eb5cae7e82a1c6aa744cd
SHA256: 50762f00ee82925d9c7539abbbe9b84ca5e7cbb5c51d7bc5f7169b7f80c3f2fd
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 6e817599ffdcd3bb5daa7488222a0441
SHA256: 249dc170bfb82bbcd0bb782778f8913d0f1640fcbc41457501b6c65fbdb02b3c
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\tr\Microsoft.VisualStudio.ServiceHub.Common.resources.dll
executable
MD5: a21f0b54ed10761aa928a7744a1ce3f4
SHA256: 4e7feb7eb3f12c5e2e712b26b19ef6defbee200dd5abaccd0031516b08b39cbd
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\handle.exe
executable
MD5: 8f06641dc82a45c4c563747ecbd44150
SHA256: e2d9a1d6103d45bb93d0a2d9c1549c143aaf656daeaa58171da56649bf7b69a0
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\CheckHyperVHost.exe
executable
MD5: 569f2080d1507210b99418cbfb5fb806
SHA256: 83df189fb2c95e487e11b07641300b350743b6725894bf5ba1e6038564ce7f11
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Setup.Service.resources.dll
executable
MD5: 1272b6266df9b1d8e315dc427929c047
SHA256: 682a192d5e6e5f24c38e63006428752e4257fd62b745766629e4455465ac4520
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\tr\Microsoft.VisualStudio.Setup.Common.resources.dll
executable
MD5: 7f2bd1689f8178900398476f815ee56f
SHA256: 6ee69f914cfdc94c71e3937e4471360c00d0021a55b7e099748b96d1ebcf45d6
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\fr\StreamJsonRpc.resources.dll
executable
MD5: aa980ff47ac878b22fd4394aeda54072
SHA256: 39064c29524fe2dcd57ea8920dab9a8607bc8666321f4341a2320926b4a2898b
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: 371dfcd9218a52fa7a4cf2b187926b47
SHA256: 7043b82592d65977d920579a2bcf695d1321515e4733ee9881cdf65ee5dc7818
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: c90fb16fab6040cbdac6d4389230a383
SHA256: f050e1e3d241613d8fc766523f76dd11825e519d9926573908914258937e5604
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\tr\Microsoft.VisualStudio.Setup.Download.resources.dll
executable
MD5: 6956476072e78c08601f9c225e6bd618
SHA256: d846c63580cfa2a84faf6d0b9cbc5541be8e6ecfc15bdb3ad7f0c3e837b8d999
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\fr\Setup.resources.dll
executable
MD5: 622c42f26dcc1dfc132d9079fec263dc
SHA256: 7fa61bd659d31dec6258d7d9bab95db0158d5c646410daaf962fb5c97c6211ea
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: ad41d7793e8e931d6edb8fe72d70c190
SHA256: df4524b35b88023f7bc4c8741776e1b4f933fe5ebf241e1ed5230fd10205b133
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 613a5bb344f9ea8510dd1a293f425ea0
SHA256: 108faf266ccf20faa4eba1f78c0756f3491ca9c8a4e80e2d332204026435ab69
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\tr\Microsoft.VisualStudio.Setup.Engine.resources.dll
executable
MD5: 05609c22fbfac215de35c4f1fc17c742
SHA256: 084fcee289760e62ca032ba7122d1d3f14bafe19ef03f181b45e4232fda91699
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\fr\Microsoft.VisualStudio.Validation.resources.dll
executable
MD5: 6cd8d9d869f03d856321beb4d056e633
SHA256: 706f418e3f7b99a0dc8b8056d3402b681405c0f2425444853ad82ddf7e6571a8
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: e27ce56b6565c66171f7fa29b240cf98
SHA256: 58e11bcc6ce7a7a2cad717340b7e3e31ab017e8c242b7c72cea19a2ba0c664ac
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\ko\StreamJsonRpc.resources.dll
executable
MD5: a8681936c80d581bcafc436da1789adf
SHA256: 22dc7e35eafa081982ef806c133bd01d2de9b9a6cd499ff808eac9413cb0d59a
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\tr\Microsoft.VisualStudio.Setup.resources.dll
executable
MD5: 963e3967aecb8a12f046c77839b2e2c1
SHA256: e9f887317c00fed18db1d72846145e7b875bb63502666c2b16ae3732ae2bd674
3208
vs_setup_bootstrapper.exe
C:\Program Files\Microsoft Visual Studio\Installer\resources\app\layout\fr\Microsoft.VisualStudio.Threading.resources.dll
executable
MD5: 2a68927d197e705816f24ca8a393c628
SHA256: 2a70f61b66348fc86a6a60cf40c96f4d8a7f903a0501891fa4c4