General Info

File name

d2ee013fdf1f7aad62315d4c27de5c88.exe

Full analysis
https://app.any.run/tasks/e064ca9f-0e0d-4872-b06c-0823a12873ee
Verdict
Malicious activity
Analysis date
12/3/2019, 01:45:49
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

d2ee013fdf1f7aad62315d4c27de5c88

SHA1

79a1c6ab1d1b9e73c00c2f717eb69d0891bfb4cc

SHA256

bf6d14f1ffa201e7fad8f3ec6f4484f51b47abc19435b3e2b796b3297d0125dd

SSDEEP

196608:fj8cTX0T39Bu/SBtgDfIRM5dce3waFevNDvH:fIcuNRtgDfIRM57AX9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • GoogleUpdateOnDemand.exe (PID: 1096)
  • CCLibrary.exe (PID: 3004)
  • setup.exe (PID: 3788)
  • node.exe (PID: 1160)
  • setup.exe (PID: 748)
  • GoogleUpdate.exe (PID: 3752)
  • GoogleUpdateSetup.exe (PID: 956)
  • GoogleUpdate.exe (PID: 616)
  • GoogleUpdate.exe (PID: 1188)
Loads dropped or rewritten executable
  • GoogleUpdate.exe (PID: 3388)
  • GoogleUpdate.exe (PID: 2604)
  • GoogleUpdate.exe (PID: 616)
  • GoogleUpdate.exe (PID: 3752)
  • GoogleUpdate.exe (PID: 3640)
  • GoogleUpdate.exe (PID: 3916)
  • node.exe (PID: 1160)
  • GoogleUpdate.exe (PID: 4088)
Changes the autorun value in the registry
  • setup.exe (PID: 748)
  • node.exe (PID: 1160)
Creates a software uninstall entry
  • setup.exe (PID: 748)
Application launched itself
  • GoogleUpdate.exe (PID: 4088)
Executed via COM
  • GoogleUpdateOnDemand.exe (PID: 1096)
Executable content was dropped or overwritten
  • 78.0.3904.108_chrome_installer.exe (PID: 3176)
  • setup.exe (PID: 748)
  • d2ee013fdf1f7aad62315d4c27de5c88.exe (PID: 2952)
  • GoogleUpdate.exe (PID: 1188)
  • GoogleUpdateSetup.exe (PID: 956)
Creates files in the program directory
  • GoogleUpdate.exe (PID: 4088)
  • GoogleUpdateSetup.exe (PID: 956)
  • setup.exe (PID: 748)
Modifies the open verb of a shell class
  • setup.exe (PID: 748)
Creates files in the user directory
  • msiexec.exe (PID: 2588)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (64.6%)
.dll
|   Win32 Dynamic Link Library (generic) (15.4%)
.exe
|   Win32 Executable (generic) (10.5%)
.exe
|   Generic Win/DOS Executable (4.6%)
.exe
|   DOS Executable Generic (4.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:04:27 22:03:27+02:00
PEType:
PE32
LinkerVersion:
14
CodeSize:
190976
InitializedDataSize:
214528
UninitializedDataSize:
null
EntryPoint:
0x1d759
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
1.3.34.11
ProductVersionNumber:
1.3.34.11
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Google LLC
FileDescription:
Google Update Setup
FileVersion:
1.3.34.11
InternalName:
Google Update Setup
LegalCopyright:
Copyright 2018 Google LLC
OriginalFileName:
GoogleUpdateSetup.exe
ProductName:
Google Update
ProductVersion:
1.3.34.11
LanguageId:
en
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
27-Apr-2019 20:03:27
Detected languages
English - United States
Debug artifacts
D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
CompanyName:
Google LLC
FileDescription:
Google Update Setup
FileVersion:
1.3.34.11
InternalName:
Google Update Setup
LegalCopyright:
Copyright 2018 Google LLC
OriginalFilename:
GoogleUpdateSetup.exe
ProductName:
Google Update
ProductVersion:
1.3.34.11
LanguageId:
en
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000110
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
27-Apr-2019 20:03:27
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0002E854 0x0002EA00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.69231
.rdata 0x00030000 0x00009A9C 0x00009C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.13286
.data 0x0003A000 0x000213D0 0x00000C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.25381
.gfids 0x0005C000 0x000000E8 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 2.11154
.rsrc 0x0005D000 0x00008000 0x00007400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.02945
.reloc 0x00065000 0x00001FCC 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.64554
Resources
1

7

8

9

10

11

12

13

14

15

16

101

102

ASKNEXTVOL

GETPASSWORD1

LICENSEDLG

RENAMEDLG

REPLACEFILEDLG

STARTDLG

Imports
    KERNEL32.dll

    gdiplus.dll

    USER32.dll (delay-loaded)

Exports

    No exports.

Screenshots

Processes

Total processes
54
Monitored processes
17
Malicious processes
8
Suspicious processes
3

Behavior graph

+
drop and start drop and start start drop and start drop and start drop and start d2ee013fdf1f7aad62315d4c27de5c88.exe cclibrary.exe no specs googleupdate.exe node.exe googleupdate.exe no specs msiexec.exe googleupdatesetup.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe 78.0.3904.108_chrome_installer.exe setup.exe setup.exe no specs googleupdateondemand.exe no specs googleupdate.exe no specs googleupdate.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2952
CMD
"C:\Users\admin\AppData\Local\Temp\d2ee013fdf1f7aad62315d4c27de5c88.exe"
Path
C:\Users\admin\AppData\Local\Temp\d2ee013fdf1f7aad62315d4c27de5c88.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Update Setup
Version
1.3.34.11
Modules
Image
c:\users\admin\appdata\local\temp\d2ee013fdf1f7aad62315d4c27de5c88.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\riched20.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\users\admin\appdata\local\google\cclibrary.exe
c:\windows\system32\sfc.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\users\admin\appdata\local\google\googleupdate.exe

PID
3004
CMD
"C:\Users\admin\AppData\Local\Google\CCLibrary.exe"
Path
C:\Users\admin\AppData\Local\Google\CCLibrary.exe
Indicators
No indicators
Parent process
d2ee013fdf1f7aad62315d4c27de5c88.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Adobe Systems Incorporated
Description
CCLibraries
Version
3.2.3.17
Modules
Image
c:\users\admin\appdata\local\google\cclibrary.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\google\libs\node.exe

PID
1188
CMD
"C:\Users\admin\AppData\Local\Google\GoogleUpdate.exe"
Path
C:\Users\admin\AppData\Local\Google\GoogleUpdate.exe
Indicators
Parent process
d2ee013fdf1f7aad62315d4c27de5c88.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Update Setup
Version
1.3.34.11
Modules
Image
c:\users\admin\appdata\local\google\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\gumb456.tmp\googleupdate.exe

PID
1160
CMD
"C:\Users\admin\AppData\Local\Google\libs\node.exe" "C:\Users\admin\AppData\Local\Google\js\server.js"
Path
C:\Users\admin\AppData\Local\Google\libs\node.exe
Indicators
Parent process
CCLibrary.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Node.js
Description
Node.js: Server-side JavaScript
Version
10.16.0
Modules
Image
c:\users\admin\appdata\local\google\libs\node.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\pcwum.dll
c:\users\admin\appdata\local\google\js\addon.node
c:\windows\system32\apphelp.dll
c:\windows\system32\msiexec.exe

PID
616
CMD
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}&lang=zh-CN&browser=2&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=defaultbrowser"
Path
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Installer
Version
1.3.34.11
Modules
Image
c:\users\admin\appdata\local\temp\gumb456.tmp\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\users\admin\appdata\local\temp\gumb456.tmp\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\gumb456.tmp\goopdateres_zh-cn.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\mpr.dll

PID
2588
CMD
msiexec.exe
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
node.exe
User
admin
Integrity Level
MEDIUM
Exit code
1768843639
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

PID
956
CMD
"C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}&lang=zh-CN&browser=2&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=defaultbrowser" /installelevated /nomitag
Path
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateSetup.exe
Indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Version:
Company
Google LLC
Description
Google Update Setup
Version
1.3.34.11
Modules
Image
c:\users\admin\appdata\local\temp\gumb456.tmp\googleupdatesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\program files\gumbc94.tmp\googleupdate.exe

PID
3752
CMD
"C:\Program Files\GUMBC94.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}&lang=zh-CN&browser=2&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=defaultbrowser" /installelevated
Path
C:\Program Files\GUMBC94.tmp\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdateSetup.exe
User
admin
Integrity Level
HIGH
Version:
Company
Google LLC
Description
Google Installer
Version
1.3.34.11
Modules
Image
c:\program files\gumbc94.tmp\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\gumbc94.tmp\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\program files\gumbc94.tmp\goopdateres_zh-cn.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe

PID
3916
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /healthcheck
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll

PID
3640
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNC4xMSIgc2hlbGxfdmVyc2lvbj0iMS4zLjMzLjIzIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezMxMDk0N0EwLTQ0OTMtNDdFMi04QjU1LTMwNTMwOTI3QTEwOH0iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiByZXF1ZXN0aWQ9InswN0E1NEI2Ri1GRkE3LTQ0NDMtODk3QS0xREMxM0M2QUIyMzN9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IHBoeXNtZW1vcnk9IjMiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjAiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IjEuMy4zNC4xMSIgbmV4dHZlcnNpb249IjEuMy4zNC4xMSIgbGFuZz0iemgtQ04iIGJyYW5kPSIiIGNsaWVudD0iIiBpaWQ9IntBNDJFN0NEMi03RjY0LUUxQzktQkY5Ni05REJEMEY5MUQwOTN9Ij48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjI1MCIvPjwvYXBwPjwvcmVxdWVzdD4
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll

PID
4088
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}&lang=zh-CN&browser=2&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=defaultbrowser" /installsource taggedmi /sessionid "{310947A0-4493-47E2-8B55-30530927A108}"
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\program files\google\update\1.3.34.11\goopdateres_zh-cn.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\qmgrprxy.dll
c:\windows\system32\bitsprx4.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\install\{314126c4-a428-4096-98cd-d51f3b136c18}\78.0.3904.108_chrome_installer.exe
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll

PID
3176
CMD
"C:\Program Files\Google\Update\Install\{314126C4-A428-4096-98CD-D51F3B136C18}\78.0.3904.108_chrome_installer.exe" --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Users\admin\AppData\Local\Temp\gui6C4C.tmp"
Path
C:\Program Files\Google\Update\Install\{314126C4-A428-4096-98CD-D51F3B136C18}\78.0.3904.108_chrome_installer.exe
Indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome Installer
Version
78.0.3904.108
Modules
Image
c:\program files\google\update\install\{314126c4-a428-4096-98cd-d51f3b136c18}\78.0.3904.108_chrome_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\cr_9f57a.tmp\setup.exe

PID
748
CMD
"C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Users\admin\AppData\Local\Temp\gui6C4C.tmp"
Path
C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\setup.exe
Indicators
Parent process
78.0.3904.108_chrome_installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome Installer
Version
78.0.3904.108
Modules
Image
c:\users\admin\appdata\local\temp\cr_9f57a.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\google\chrome\application\chrome.exe

PID
3788
CMD
C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\setup.exe --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Windows\TEMP\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=78.0.3904.108 --initial-client-data=0x10c,0x114,0x118,0x108,0x11c,0xd6e218,0xd6e228,0xd6e234
Path
C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\setup.exe
Indicators
No indicators
Parent process
setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome Installer
Version
78.0.3904.108
Modules
Image
c:\users\admin\appdata\local\temp\cr_9f57a.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\winmm.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
1096
CMD
"C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe" -Embedding
Path
C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Update
Version
1.3.34.11
Modules
Image
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe

PID
3388
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdateOnDemand.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll

PID
2604
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNC4xMSIgc2hlbGxfdmVyc2lvbj0iMS4zLjMzLjIzIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezMxMDk0N0EwLTQ0OTMtNDdFMi04QjU1LTMwNTMwOTI3QTEwOH0iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiByZXF1ZXN0aWQ9Ins4REU0RkFBQi00QzRGLTQzQkUtOTdCNC0zQkRCQ0RCN0I2RDl9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IHBoeXNtZW1vcnk9IjMiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjAiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezhBNjlEMzQ1LUQ1NjQtNDYzQy1BRkYxLUE2OUQ5RTUzMEY5Nn0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249Ijc4LjAuMzkwNC4xMDgiIGFwPSJ4NjQtc3RhYmxlLXN0YXRzZGVmXzEiIGxhbmc9InpoLUNOIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iNDYxIiBpbnN0YWxsZGF0ZT0iNDI1NiIgaWlkPSJ7QTQyRTdDRDItN0Y2NC1FMUM5LUJGOTYtOURCRDBGOTFEMDkzfSIgY29ob3J0PSIxOmd1L2kxOToiIGNvaG9ydG5hbWU9IlN0YWJsZSBJbnN0YWxscyBPbmx5Ij48ZXZlbnQgZXZlbnR0eXBlPSI5IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGRvd25sb2FkZXI9ImJpdHMiIHVybD0iaHR0cDovL3JlZGlyZWN0b3IuZ3Z0MS5jb20vZWRnZWRsL3JlbGVhc2UyL2Nocm9tZS9BUG4xcHdPOVZBTFNjejd1dDBrSy1SVV83OC4wLjM5MDQuMTA4Lzc4LjAuMzkwNC4xMDhfY2hyb21lX2luc3RhbGxlci5leGUiIGRvd25sb2FkZWQ9IjU2ODA1MTIwIiB0b3RhbD0iNTY4MDUxMjAiIGRvd25sb2FkX3RpbWVfbXM9IjM4Mzc1Ii8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIvPjxldmVudCBldmVudHR5cGU9IjYiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzb3VyY2VfdXJsX2luZGV4PSIwIiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iMzAwMCIgZG93bmxvYWRfdGltZV9tcz0iMzk0NTMiIGRvd25sb2FkZWQ9IjU2ODA1MTIwIiB0b3RhbD0iNTY4MDUxMjAiIGluc3RhbGxfdGltZV9tcz0iOTI5NyIvPjxkYXRhIG5hbWU9Imluc3RhbGwiIGluZGV4PSJkZWZhdWx0YnJvd3NlciIvPjwvYXBwPjwvcmVxdWVzdD4
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll

Registry activity

Total events
2780
Read events
1120
Write events
1640
Delete events
20

Modification events

PID
Process
Operation
Key
Name
Value
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1160
node.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
CCLibrary
C:\Users\admin\AppData\Local\Google\CCLibrary.exe
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
EnableFileTracing
0
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
EnableConsoleTracing
0
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
FileTracingMask
4294901760
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
ConsoleTracingMask
4294901760
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
MaxFileSize
1048576
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
FileDirectory
%windir%\tracing
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
EnableFileTracing
0
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
EnableConsoleTracing
0
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
FileTracingMask
4294901760
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
ConsoleTracingMask
4294901760
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
MaxFileSize
1048576
2588
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
FileDirectory
%windir%\tracing
2588
msiexec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2588
msiexec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2588
msiexec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2588
msiexec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3752
GoogleUpdate.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{07A54B6F-FFA7-4443-897A-1DC13C6AB233}
3752
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
3752
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
iid
{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}
3752
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{07A54B6F-FFA7-4443-897A-1DC13C6AB233}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{07A54B6F-FFA7-4443-897A-1DC13C6AB233}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{430FD4D0-B729-4F61-AA34-91526481799D}" version="1.3.34.11" nextversion="1.3.34.11" lang="zh-CN" brand="" client="" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}"><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" install_time_ms="250"/></app></request>
3752
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{07A54B6F-FFA7-4443-897A-1DC13C6AB233}
PersistedPingTime
132198075723781250
3640
GoogleUpdate.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
3640
GoogleUpdate.exe
write
HKEY_CURRENT_USER\Software\Google\Update\proxy
source
direct
4088
GoogleUpdate.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
4088
GoogleUpdate.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{7D180611-9D84-47E6-AC0A-0786B68DADE0}
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{7D180611-9D84-47E6-AC0A-0786B68DADE0}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" requestid="{7D180611-9D84-47E6-AC0A-0786B68DADE0}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{7D180611-9D84-47E6-AC0A-0786B68DADE0}
PersistedPingTime
132198075728156250
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
pv
75.0.3770.100
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
3
4088
GoogleUpdate.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
4088
GoogleUpdate.exe
write
HKEY_CURRENT_USER\Software\Google\Update\proxy
source
auto
4088
GoogleUpdate.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
ping_freshness
{16FD4DFB-D523-4D49-B1C2-F213F37F1772}
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\cohort
1:gu/i19:
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\cohort
hint
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\cohort
name
Stable Installs Only
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
4
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{8A69D345-D564-463C-AFF1-A69D9E530F96}" version="" nextversion="78.0.3904.108" ap="x64-stable-statsdef_1" lang="zh-CN" brand="" client="" installage="461" installdate="4256" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}" cohort="1:gu/i19:" cohortname="Stable Installs Only"><event eventtype="9" eventresult="1" errorcode="0" extracode1="0"/><data name="install" index="defaultbrowser"/></app></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingTime
132198075759562500
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
4294967295
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
5
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{8A69D345-D564-463C-AFF1-A69D9E530F96}" version="" nextversion="78.0.3904.108" ap="x64-stable-statsdef_1" lang="zh-CN" brand="" client="" installage="461" installdate="4256" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}" cohort="1:gu/i19:" cohortname="Stable Installs Only"><event eventtype="9" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="5" eventresult="1" errorcode="0" extracode1="0"/><data name="install" index="defaultbrowser"/></app></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingTime
132198075765968750
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
7
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
843926
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
190703
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
2
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
94197
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
4
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
73047
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
5
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
49762
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
7
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
45040
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
9
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
33794
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
11
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
28524
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
13
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
27580
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
15
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
26069
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
17
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
25489
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
18
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
24908
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
20
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
24409
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
22
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
23748
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
24
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
23168
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
26
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
22426
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
28
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
22007
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
29
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
21498
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
31
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
21888
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
33
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
21357
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
35
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
20606
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
36
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
19935
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
38
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
19400
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
40
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
18744
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
42
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
18132
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
44
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
17591
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
46
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
16349
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
47
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
15717
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
49
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
15189
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
51
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
14657
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
53
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
14028
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
55
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
13493
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
57
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
12910
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
59
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
12247
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
60
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
11668
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
62
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
11502
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
64
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
10896
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
66
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
10302
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
68
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
9703
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
70
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
9103
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
71
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
8503
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
73
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
7903
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
75
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
7303
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
77
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
6463
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
79
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
5885
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
81
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
5286
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
83
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
4728
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
84
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
4133
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
86
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
3557
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
88
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
2981
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
90
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
2406
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
92
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
1830
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
94
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
1253
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
95
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
859
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
97
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
255
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
99
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadTimeRemainingMs
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
DownloadProgressPercent
100
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{8A69D345-D564-463C-AFF1-A69D9E530F96}" version="" nextversion="78.0.3904.108" ap="x64-stable-statsdef_1" lang="zh-CN" brand="" client="" installage="461" installdate="4256" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}" cohort="1:gu/i19:" cohortname="Stable Installs Only"><event eventtype="9" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="5" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0" downloader="bits" url="http://redirector.gvt1.com/edgedl/release2/chrome/APn1pwO9VALScz7ut0kK-RU_78.0.3904.108/78.0.3904.108_chrome_installer.exe" downloaded="56805120" total="56805120" download_time_ms="38375"/><data name="install" index="defaultbrowser"/></app></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingTime
132198076160656250
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{8A69D345-D564-463C-AFF1-A69D9E530F96}" version="" nextversion="78.0.3904.108" ap="x64-stable-statsdef_1" lang="zh-CN" brand="" client="" installage="461" installdate="4256" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}" cohort="1:gu/i19:" cohortname="Stable Installs Only"><event eventtype="9" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="5" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0" downloader="bits" url="http://redirector.gvt1.com/edgedl/release2/chrome/APn1pwO9VALScz7ut0kK-RU_78.0.3904.108/78.0.3904.108_chrome_installer.exe" downloaded="56805120" total="56805120" download_time_ms="38375"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0"/><data name="install" index="defaultbrowser"/></app></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingTime
132198076160812500
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
11
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{8A69D345-D564-463C-AFF1-A69D9E530F96}" version="" nextversion="78.0.3904.108" ap="x64-stable-statsdef_1" lang="zh-CN" brand="" client="" installage="461" installdate="4256" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}" cohort="1:gu/i19:" cohortname="Stable Installs Only"><event eventtype="9" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="5" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0" downloader="bits" url="http://redirector.gvt1.com/edgedl/release2/chrome/APn1pwO9VALScz7ut0kK-RU_78.0.3904.108/78.0.3904.108_chrome_installer.exe" downloaded="56805120" total="56805120" download_time_ms="38375"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="6" eventresult="1" errorcode="0" extracode1="0"/><data name="install" index="defaultbrowser"/></app></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingTime
132198076167687500
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
lang
zh-CN
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
ap
x64-stable-statsdef_1
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
browser
2
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallTimeRemainingMs
4294967295
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallProgressPercent
100
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
13
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallProgressPercent
24
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallProgressPercent
37
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallProgressPercent
56
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallProgressPercent
75
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallProgressPercent
81
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
LastInstallerResult
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
LastInstallerError
2
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
LastInstallerSuccessLaunchCmdLine
"C:\Program Files\Google\Chrome\Application\chrome.exe"
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
LastInstallerResult
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
LastInstallerError
2
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
LastInstallerSuccessLaunchCmdLine
"C:\Program Files\Google\Chrome\Application\chrome.exe"
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
pv
78.0.3904.108
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
iid
{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
LastCheckSuccess
1575334026
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingString
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.34.11" shell_version="1.3.33.23" ismachine="1" sessionid="{310947A0-4493-47E2-8B55-30530927A108}" installsource="taggedmi" requestid="{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}" dedup="cr" domainjoined="0"><hw physmemory="3" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="6.1.7601.0" sp="Service Pack 1" arch="x86"/><app appid="{8A69D345-D564-463C-AFF1-A69D9E530F96}" version="" nextversion="78.0.3904.108" ap="x64-stable-statsdef_1" lang="zh-CN" brand="" client="" installage="461" installdate="4256" iid="{A42E7CD2-7F64-E1C9-BF96-9DBD0F91D093}" cohort="1:gu/i19:" cohortname="Stable Installs Only"><event eventtype="9" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="5" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0" downloader="bits" url="http://redirector.gvt1.com/edgedl/release2/chrome/APn1pwO9VALScz7ut0kK-RU_78.0.3904.108/78.0.3904.108_chrome_installer.exe" downloaded="56805120" total="56805120" download_time_ms="38375"/><event eventtype="1" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="6" eventresult="1" errorcode="0" extracode1="0"/><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" source_url_index="0" update_check_time_ms="3000" download_time_ms="39453" downloaded="56805120" total="56805120" install_time_ms="9297"/><data name="install" index="defaultbrowser"/></app></request>
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\PersistedPings\{8DE4FAAB-4C4F-43BE-97B4-3BDBCDB7B6D9}
PersistedPingTime
132198076260968750
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
InstallTimeRemainingMs
0
4088
GoogleUpdate.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState
StateValue
14
3176
78.0.3904.108_chrome_installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
ap
x64-stable-statsdef_1-full
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\LocalServer32
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{708860E0-F641-4611-8895-7D867DD3675B}
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{708860E0-F641-4611-8895-7D867DD3675B}
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{463ABECF-410D-407F-8AF5-0DF35A005CC8}
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\ProxyStubClsid32
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\TypeLib
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\1.0
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\1.0\0
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\1.0\0\win32
748
setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\1.0\0\win64
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
18
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
24
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
37
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
43
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
49
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
56
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
UninstallString
C:\Program Files\Google\Chrome\Application\78.0.3904.108\Installer\setup.exe
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
UninstallArguments
--uninstall --msi --system-level --verbose-logging
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}
name
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}
pv
78.0.3904.108
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
StubPath
"C:\Program Files\Google\Chrome\Application\78.0.3904.108\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Localized Name
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
IsInstalled
1
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Version
43,0,0,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade
CommandLine
"C:\Program Files\Google\Chrome\Application\78.0.3904.108\Installer\setup.exe" --on-os-upgrade --system-level --verbose-logging
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade
AutoRunOnOSUpgrade
1
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\store-dmtoken
CommandLine
"C:\Program Files\Google\Chrome\Application\78.0.3904.108\Installer\setup.exe" --store-dmtoken=%1 --system-level --verbose-logging
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\store-dmtoken
WebAccessible
1
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\LocalServer32
"C:\Program Files\Google\Chrome\Application\78.0.3904.108\notification_helper.exe"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\LocalServer32
ServerExecutable
C:\Program Files\Google\Chrome\Application\78.0.3904.108\notification_helper.exe
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{708860E0-F641-4611-8895-7D867DD3675B}
AppID
{708860E0-F641-4611-8895-7D867DD3675B}
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{708860E0-F641-4611-8895-7D867DD3675B}
LocalService
GoogleChromeElevationService
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\TypeLib
{463ABECF-410D-407F-8AF5-0DF35A005CC8}
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\1.0\0\win32
C:\Program Files\Google\Chrome\Application\78.0.3904.108\elevation_service.exe
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{463ABECF-410D-407F-8AF5-0DF35A005CC8}\1.0\0\win64
C:\Program Files\Google\Chrome\Application\78.0.3904.108\elevation_service.exe
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
msi
1
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
62
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
68
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
75
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
74
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
75
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
76
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
81
748
setup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Chrome
CategoryCount
1
748
setup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Chrome
TypesSupported
7
748
setup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Chrome
CategoryMessageFile
C:\Program Files\Google\Chrome\Application\78.0.3904.108\eventlog_provider.dll
748
setup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Chrome
EventMessageFile
C:\Program Files\Google\Chrome\Application\78.0.3904.108\eventlog_provider.dll
748
setup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Chrome
ParameterMessageFile
C:\Program Files\Google\Chrome\Application\78.0.3904.108\eventlog_provider.dll
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ChromeHTML
Chrome HTML Document
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ChromeHTML\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ChromeHTML\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
Path
C:\Program Files\Google\Chrome\Application
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.html\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdf\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.shtml\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.svg\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xht\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xhtml\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.webp\OpenWithProgids
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\InstallInfo
ReinstallCommand
"C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\InstallInfo
HideIconsCommand
"C:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\InstallInfo
ShowIconsCommand
"C:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\InstallInfo
IconsVisible
1
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
Google Chrome
Software\Clients\StartMenuInternet\Google Chrome\Capabilities
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities
ApplicationDescription
Google Chrome is a web browser that runs webpages and applications with lightning speed. It's fast, stable, and easy to use. Browse the web more safely with malware and phishing protection built into Google Chrome.
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities
ApplicationIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities
ApplicationName
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\Startmenu
StartMenuInternet
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.htm
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.html
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.pdf
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.shtml
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.svg
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.xht
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.xhtml
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\FileAssociations
.webp
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
ftp
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
http
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
https
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
irc
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
mailto
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
mms
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
news
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
nntp
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
sms
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
smsto
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
snews
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
tel
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
urn
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\Capabilities\URLAssociations
webcal
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
77
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
78
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
79
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
80
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
81
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
82
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
83
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
84
748
setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice
Progid
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
85
748
setup.exe
write
HKEY_CLASSES_ROOT\.htm
ChromeHTML
748
setup.exe
write
HKEY_CLASSES_ROOT\.html
ChromeHTML
748
setup.exe
write
HKEY_CLASSES_ROOT\.shtml
ChromeHTML
748
setup.exe
write
HKEY_CLASSES_ROOT\.xht
ChromeHTML
748
setup.exe
write
HKEY_CLASSES_ROOT\.xhtml
ChromeHTML
748
setup.exe
write
HKEY_CLASSES_ROOT\ftp
URL Protocol
748
setup.exe
write
HKEY_CLASSES_ROOT\ftp\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\ddeexec
748
setup.exe
write
HKEY_CLASSES_ROOT\ftp\shell
open
748
setup.exe
write
HKEY_CLASSES_ROOT\http
URL Protocol
748
setup.exe
write
HKEY_CLASSES_ROOT\http\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_CLASSES_ROOT\http\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_CLASSES_ROOT\http\shell\open\ddeexec
748
setup.exe
write
HKEY_CLASSES_ROOT\http\shell
open
748
setup.exe
write
HKEY_CLASSES_ROOT\https
URL Protocol
748
setup.exe
write
HKEY_CLASSES_ROOT\https\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_CLASSES_ROOT\https\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_CLASSES_ROOT\https\shell\open\ddeexec
748
setup.exe
write
HKEY_CLASSES_ROOT\https\shell
open
748
setup.exe
write
HKEY_CURRENT_USER\Software\Clients\StartmenuInternet
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.html
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.shtml
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xht
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xhtml
ChromeHTML
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp
URL Protocol
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\shell\open\ddeexec
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\shell
open
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http
URL Protocol
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell\open\ddeexec
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell
open
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https
URL Protocol
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https\shell\open\ddeexec
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https\shell
open
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet
Google Chrome
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
86
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
87
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerProgress
100
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerResult
0
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerError
2
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
InstallerSuccessLaunchCmdLine
"C:\Program Files\Google\Chrome\Application\chrome.exe"
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EDF60E6CC0B1623E904001B99652E9A\InstallProperties
DisplayVersion
78.0.3904.108
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6E06FDE9-B0CC-3261-9E40-00B19956E2A9}
DisplayVersion
78.0.3904.108
748
setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
ap
x64-stable-statsdef_1

Files activity

Executable files
150
Suspicious files
3
Text files
7
Unknown types
32

Dropped files

PID
Process
Filename
Type
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
C:\Users\admin\AppData\Local\Google\GoogleUpdate.exe
executable
MD5: 8a401f5047e3012b8c53905a08973089
SHA256: b3def08dbad77219d673e9f50d990593ceeaf2e9124356eb2b329a893daf7bb4
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ja.dll
executable
MD5: 9a2fc61130b68ee41476d63f415447f1
SHA256: a3a60744f7c4853eb7e44b1840a6d3def05f3bbc53dbfec0c64b0de5e8bb5e2c
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdate.dll
executable
MD5: 69d1bf5384cea587e6cc69ac827cc02d
SHA256: d8f9c6a2e3f784e4a9c9dd714e1fbfea1883b920216dc01ad9d56700b17c0671
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_lt.dll
executable
MD5: de7fd22ca9efb8f45842bef8b0ddd8b1
SHA256: e0bc1b946e50ad5aa24c016524da2e251530062704178ae0f51f9af02a89e1fc
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateBroker.exe
executable
MD5: 700c3948a21d47d991ef8daf7a176ae9
SHA256: d1ffd6fae6250d7f03621e54d7b8dac9882ff98e7fb2cac174c5a34a0f157bdd
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_fa.dll
executable
MD5: 54649821e243e218ffa10802191055b6
SHA256: 5a397ab4774fd5a7f0d7e0d4871812fa92e2f9e5f595e94a4b652fecc29674ae
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_bg.dll
executable
MD5: c2ebb44d01d7a7d5b61aca6f82e16504
SHA256: d3f0fb94c9cfac96d685cc47e9456ad86d1b5bcf03bd0db11255d33a2a360adb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_gu.dll
executable
MD5: f42aad7002e1a4ac1d455fa51852b32c
SHA256: 215c700fac5caed6e5073e10cd5a07e0409cf0107903476e9a52dc5494ff6389
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_cs.dll
executable
MD5: ce1dd611a19e30291631a9657afd96b3
SHA256: 0a8166e3963bd3e754487c1b57e84a429e1c1ec483d273da5ef2cc5e3a6115de
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_es.dll
executable
MD5: c6b78770986dcdcf2e873059a33fd64b
SHA256: 69f67cc945fdd476b6d43f213da7a6cb35ac9194efaa50ee8a1c5fbfacac7c7f
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\d3dcompiler_47.dll
executable
MD5: 587a415cd5ac2069813adef5f7685021
SHA256: 2ad0d4987fc4624566b190e747c9d95038443956ed816abfd1e2d389b5ec0851
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\psmachine.dll
executable
MD5: 64dd97e3eafe04d5e41f0f90111e50e2
SHA256: c7ac5ffa7c18c96369137cc81a57f9293d8585dcdbdddabb34363f514359f4ce
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\npGoogleUpdate3.dll
executable
MD5: cdbe4728d075ca5050b3b9fa7138f8b8
SHA256: 051c42124192595ec6d22577e4870fad2a8ac52f04a43cb77372a99d48a9b718
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_en-GB.dll
executable
MD5: 4281d3c6a33aae2ace4fdd78ac7b6b33
SHA256: ebd5c1b6f76eb41a59b1118a16a45db8fb45b32a0dabe5f919c5d209f1e4cf85
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_it.dll
executable
MD5: e476d68395afc1f1468ea27e7d801eab
SHA256: 44bab1dc2526c25560493fbd4d5dbb8c0cfdf53f99cbb6b9ed0ba765fb39bcab
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_en-GB.dll
executable
MD5: 4281d3c6a33aae2ace4fdd78ac7b6b33
SHA256: ebd5c1b6f76eb41a59b1118a16a45db8fb45b32a0dabe5f919c5d209f1e4cf85
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_de.dll
executable
MD5: 53a1f85365b0a7e9f9b28171c44a057e
SHA256: 9e3a8acf0bf2655af754add6cc10e12cfa10a68da256e93192644a4fe3c8c7c9
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_el.dll
executable
MD5: d052cadd807c25c72886906a9efbc86e
SHA256: 47fd4fa0a2ef55bf44d00f9abe231dcc053972a04b09e9ac005f37f7926498cb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_id.dll
executable
MD5: 0abb138c12fdf76e83704895273ba314
SHA256: 7e676cf463cdc3f7f8ab3e41edc5dab966a86681ec4989ecc74d460cd1d56b60
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_fr.dll
executable
MD5: 77fd989107f16f1749b4160c1f0339f4
SHA256: 816361339757f2f9bbef560c902d4207ce6328a3506570e9b1df1e65f77f989c
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ca.dll
executable
MD5: 038ef0dee664c858cdd550e717849c9c
SHA256: 6d682e1347068253231be39136da2774255f758a4c8dc056f06e2bf875a3bdc1
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_en.dll
executable
MD5: 5473d86e3d71ecbea1ece30abf01cd8f
SHA256: b036bcb285a4eac4fe744b88c03a2e553132c9896d784ce95effb437973134ae
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_lv.dll
executable
MD5: bcc3f87f93fa8c9ff8efbca84abd4f20
SHA256: fc52bcaa4081a8bf597b6cdca4981c9b29b59bac40f8307fa334a3485d2009d9
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_fi.dll
executable
MD5: 8f20a78be087a95b80f1162ceba79b46
SHA256: ba9494dec1273c3a5f629e4cd0990beea6f35168ab940693fe179f111cfa9a9b
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateComRegisterShell64.exe
executable
MD5: 396ba164448844fcd0c72dd802ac7db6
SHA256: f3ada0bb7459836ba250314ea6d417694c974445f0f7218ea8a48b60c557bb89
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_de.dll
executable
MD5: 53a1f85365b0a7e9f9b28171c44a057e
SHA256: 9e3a8acf0bf2655af754add6cc10e12cfa10a68da256e93192644a4fe3c8c7c9
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_hi.dll
executable
MD5: a5a40fde77ce0330572603819f7eab1a
SHA256: 1e19516dacf3e895e632cfa6e863d4896a5847281602c16cf3995c107860888e
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_et.dll
executable
MD5: b1583b0eb3b3c938f5f16cfae1022601
SHA256: 82a6a6d661093a2310660e49a171b2bbcea4ad2d2485074b82c6969eeefd825d
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ar.dll
executable
MD5: 73b513e081a75b2419a1e4ff96ea7a01
SHA256: f2831ccdd15dedeeb7a097bcdb49ee31831274a3171f11809ea11c69b232b953
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_es-419.dll
executable
MD5: babcc3d7ac72bb5fcbf504b960b7a233
SHA256: fce66f6407d801d0a8b6d47c7286622cb5d800d7520f5c14ac162fa3145dbfc1
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_iw.dll
executable
MD5: 0da881f72338a4fb295a3fb837a696e5
SHA256: 8c7a9d6f96d007d9557eea5009ce20b7d1be0334aa7d8168d79c9867a733a932
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateWebPlugin.exe
executable
MD5: a2a18ae5f51bd129ec673b22d8df497e
SHA256: 2f5025ffa478854b92626515b3187fa2bbad7ea064079ac804d54482dc30b92a
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_gu.dll
executable
MD5: f42aad7002e1a4ac1d455fa51852b32c
SHA256: 215c700fac5caed6e5073e10cd5a07e0409cf0107903476e9a52dc5494ff6389
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ca.dll
executable
MD5: 038ef0dee664c858cdd550e717849c9c
SHA256: 6d682e1347068253231be39136da2774255f758a4c8dc056f06e2bf875a3bdc1
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_fi.dll
executable
MD5: 8f20a78be087a95b80f1162ceba79b46
SHA256: ba9494dec1273c3a5f629e4cd0990beea6f35168ab940693fe179f111cfa9a9b
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateHelper.msi
executable
MD5: 202b7ec9d41cda7ecc9a5db38301ab9f
SHA256: 28280e562ea8a542551505a1944f98a723f31a18b1ba69f59431245e432d2779
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\psmachine_64.dll
executable
MD5: 100939cc975c159c589cebd0479775f1
SHA256: da372f0567004d6a5ea481203c955011b41dc6d1a856482cac0f0d54db66fa54
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_et.dll
executable
MD5: b1583b0eb3b3c938f5f16cfae1022601
SHA256: 82a6a6d661093a2310660e49a171b2bbcea4ad2d2485074b82c6969eeefd825d
3176
78.0.3904.108_chrome_installer.exe
C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\setup.exe
executable
MD5: 09aee366d5bd812d22e0690421a096a8
SHA256: 46d34a55755180d0bd23330448cd42ebaf8bf40c2e12767bebbc51c8f79cf67c
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_en.dll
executable
MD5: 5473d86e3d71ecbea1ece30abf01cd8f
SHA256: b036bcb285a4eac4fe744b88c03a2e553132c9896d784ce95effb437973134ae
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_fil.dll
executable
MD5: f230b256bb15dc4d6c3c70895185bb0b
SHA256: abb5511af0c804210152ade4e3d140e586932aa078db535f3f240f2ad8bf3c45
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_da.dll
executable
MD5: db5b3a59d09111bcd39c20f626b474bd
SHA256: 79ffd7f3efccf614f7a1ed8ffdb49623694bc1b179c6f435ca56464a0526c57c
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_fr.dll
executable
MD5: 77fd989107f16f1749b4160c1f0339f4
SHA256: 816361339757f2f9bbef560c902d4207ce6328a3506570e9b1df1e65f77f989c
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdate.exe
executable
MD5: 82f657b0aee67a6a560321cf0927f9f7
SHA256: 794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7aca6120a11
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateCore.exe
executable
MD5: cecfd51c91c3aa81093460598c5d02a2
SHA256: a055856dcc22687bcbaa828342c851f87dd9de74dc5d647e7799d8ec4d7be0de
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_cs.dll
executable
MD5: ce1dd611a19e30291631a9657afd96b3
SHA256: 0a8166e3963bd3e754487c1b57e84a429e1c1ec483d273da5ef2cc5e3a6115de
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_fil.dll
executable
MD5: f230b256bb15dc4d6c3c70895185bb0b
SHA256: abb5511af0c804210152ade4e3d140e586932aa078db535f3f240f2ad8bf3c45
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleCrashHandler.exe
executable
MD5: a2d8bef0cca959e4beb16de982e3771c
SHA256: aff4f2d3049b10893265524f4f1eeb297a60a9414f80ea3695bf1c58de2bc43d
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ko.dll
executable
MD5: 33a88023facdd939c6c14cb692cd55e7
SHA256: 5b5feaa8f9f9621c63fdedba977c24c4a4519b3966e2d6e445a0ec9b2caa8a54
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_bn.dll
executable
MD5: 685ed2907a9d297d86ba33667b760086
SHA256: edbaf1e2ac0c335972ede1be0d425e9c8be4c68e4987778e6ae28f046e5d0d9a
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ml.dll
executable
MD5: c75102b45b2086b3508b6c1258ddb604
SHA256: 8dd0d64d6883c721087e0f58b5c195893f0fb2451468fe5eccc7a9f44f3d1537
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ta.dll
executable
MD5: 36c0dee9d410cef6dd3178d7fc405810
SHA256: 0df14319ce6648a457185c5214eda3595da1001cd495d90743498435ff1348ee
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\psuser.dll
executable
MD5: 0f2166b652db61efaf7da3beebcfda65
SHA256: 2760dafa83722514e76aab3daed075750933db3d03c27d34d52b1c122f5a4113
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateCore.exe
executable
MD5: cecfd51c91c3aa81093460598c5d02a2
SHA256: a055856dcc22687bcbaa828342c851f87dd9de74dc5d647e7799d8ec4d7be0de
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_kn.dll
executable
MD5: 072f51e42208a3d311105ef2fd72a883
SHA256: 77d6d93944a212f7efb2455f46db20277e0a5a4fada9a04a0d7392c5aa30cc22
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ur.dll
executable
MD5: 002e1990162182adc8b81a7e5f1a85e5
SHA256: 8d476b5e01268c462d994c0799ea4bdd01cbeeefeb546eacc8b51e2c1ddda438
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_da.dll
executable
MD5: db5b3a59d09111bcd39c20f626b474bd
SHA256: 79ffd7f3efccf614f7a1ed8ffdb49623694bc1b179c6f435ca56464a0526c57c
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ar.dll
executable
MD5: 73b513e081a75b2419a1e4ff96ea7a01
SHA256: f2831ccdd15dedeeb7a097bcdb49ee31831274a3171f11809ea11c69b232b953
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_hr.dll
executable
MD5: 41b96846b3e594d215e049bc6e44e7d5
SHA256: f53fa99736059d03ca35499f15d39be942d6f3633d47942e98a79d423aeccacd
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_uk.dll
executable
MD5: 1704be0e60765c931b5a2aed62ed2ed3
SHA256: b8027ca5e88df6fbf11705cc312a63d5659d2abb0d826dcc21255b72efbfc681
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleCrashHandler64.exe
executable
MD5: 30c7cbced8e3689e30299cabad4b9ac7
SHA256: 296f1bc3a9e0210ada077895deafb9969aa8073189f1f3eb0736e9e87d17bb05
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_bg.dll
executable
MD5: c2ebb44d01d7a7d5b61aca6f82e16504
SHA256: d3f0fb94c9cfac96d685cc47e9456ad86d1b5bcf03bd0db11255d33a2a360adb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_no.dll
executable
MD5: dcf2797b1d7a5554b2b133d0484e8b08
SHA256: 178736becebb2d2e1081f0a6345fff39b6c47a52f0f87a61f3c32827e7957e18
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_pt-PT.dll
executable
MD5: 5a45a26a54f413fc9ae3010432ac28cf
SHA256: d2ed2b685d8c5352cca042ec2df9c9ac9b3dc1129d3e0a4c09c31956cd0ae105
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_es.dll
executable
MD5: c6b78770986dcdcf2e873059a33fd64b
SHA256: 69f67cc945fdd476b6d43f213da7a6cb35ac9194efaa50ee8a1c5fbfacac7c7f
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_am.dll
executable
MD5: 2e4a126b96812387b4b2287f0ac9984e
SHA256: 3593fb2cbdbe626f0162e2fd279f63447fb23591d68e460eed338410ea765f3c
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_hu.dll
executable
MD5: 3b8977206e495c4c64273009e5a57f9b
SHA256: d815413523556b0d5a872c5a8a62a80bfb939e52c9d319054ef8b54a68928bdb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_zh-TW.dll
executable
MD5: 8b78d5f5ecdd454911bef4c211f12875
SHA256: fb8f75752260ac1718ce82eb6e69ecbfd5623555ef9bbf32cb20076d23719405
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_bn.dll
executable
MD5: 685ed2907a9d297d86ba33667b760086
SHA256: edbaf1e2ac0c335972ede1be0d425e9c8be4c68e4987778e6ae28f046e5d0d9a
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleCrashHandler64.exe
executable
MD5: 30c7cbced8e3689e30299cabad4b9ac7
SHA256: 296f1bc3a9e0210ada077895deafb9969aa8073189f1f3eb0736e9e87d17bb05
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateSetup.exe
executable
MD5: 8a401f5047e3012b8c53905a08973089
SHA256: b3def08dbad77219d673e9f50d990593ceeaf2e9124356eb2b329a893daf7bb4
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_sr.dll
executable
MD5: 964bdde2f1023e01412898233d72ea9d
SHA256: b8d502c1edaeb2a9250c0d3ed6ab180500be1a7e57cf20848fefc3b8048bda45
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_el.dll
executable
MD5: d052cadd807c25c72886906a9efbc86e
SHA256: 47fd4fa0a2ef55bf44d00f9abe231dcc053972a04b09e9ac005f37f7926498cb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\psmachine_64.dll
executable
MD5: 100939cc975c159c589cebd0479775f1
SHA256: da372f0567004d6a5ea481203c955011b41dc6d1a856482cac0f0d54db66fa54
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_zh-TW.dll
executable
MD5: 8b78d5f5ecdd454911bef4c211f12875
SHA256: fb8f75752260ac1718ce82eb6e69ecbfd5623555ef9bbf32cb20076d23719405
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ru.dll
executable
MD5: af3349f27fc5996c634bcc5545108a55
SHA256: 5aac683af9938cc98996f153bdfbed7319fc08a406ef801119e3a64f77ec6942
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_fa.dll
executable
MD5: 54649821e243e218ffa10802191055b6
SHA256: 5a397ab4774fd5a7f0d7e0d4871812fa92e2f9e5f595e94a4b652fecc29674ae
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\psuser_64.dll
executable
MD5: 19689751dd5a2643633d41bc7a966613
SHA256: 68c32e6c8f449cddb5f085265d7be84b8e9317a5ed113672fc7c9ba57efbe512
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_pl.dll
executable
MD5: 16767444bef259c44868446eb88bdea2
SHA256: 1e12db31f943e5fbcf44c408ab1dea16347eab61eb5851e673857842ca4f9ce2
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_pl.dll
executable
MD5: 16767444bef259c44868446eb88bdea2
SHA256: 1e12db31f943e5fbcf44c408ab1dea16347eab61eb5851e673857842ca4f9ce2
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_am.dll
executable
MD5: 2e4a126b96812387b4b2287f0ac9984e
SHA256: 3593fb2cbdbe626f0162e2fd279f63447fb23591d68e460eed338410ea765f3c
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateWebPlugin.exe
executable
MD5: a2a18ae5f51bd129ec673b22d8df497e
SHA256: 2f5025ffa478854b92626515b3187fa2bbad7ea064079ac804d54482dc30b92a
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_no.dll
executable
MD5: dcf2797b1d7a5554b2b133d0484e8b08
SHA256: 178736becebb2d2e1081f0a6345fff39b6c47a52f0f87a61f3c32827e7957e18
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_sv.dll
executable
MD5: cb51bc64dc2e3f1976af760830389773
SHA256: 0eb33c5e897c3bd154e1688574a8bc4f876146306f71bc25dbd13d52b966bd3a
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\psuser_64.dll
executable
MD5: 19689751dd5a2643633d41bc7a966613
SHA256: 68c32e6c8f449cddb5f085265d7be84b8e9317a5ed113672fc7c9ba57efbe512
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\psmachine.dll
executable
MD5: 64dd97e3eafe04d5e41f0f90111e50e2
SHA256: c7ac5ffa7c18c96369137cc81a57f9293d8585dcdbdddabb34363f514359f4ce
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_sk.dll
executable
MD5: 5e41887a7a732dcddc9589840bcc9402
SHA256: 22e6c17f2c519dd9d0c878175b609205f4690c386d70e2636d4b83f55f31b419
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_sk.dll
executable
MD5: 5e41887a7a732dcddc9589840bcc9402
SHA256: 22e6c17f2c519dd9d0c878175b609205f4690c386d70e2636d4b83f55f31b419
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_is.dll
executable
MD5: 4c954e97257e899d5941e190fcef8ca9
SHA256: c14d1ce67e2a671feb5cfab3176cb0c73b31585ba32d40d9f21b1a892c1b2e20
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateOnDemand.exe
executable
MD5: 597cb67524c8e93909696845d60a1647
SHA256: 68f5e571fa04f07b33b82c2f7e4354dec80f037ccf419722c26fe091f649ad39
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_sw.dll
executable
MD5: 15a7db5d784745f4c8f06ad17c062bb0
SHA256: 51fea2ef842076e85df77fc809330805574c19cf4f9723a09ae9ce24a92591d8
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_zh-CN.dll
executable
MD5: 0ffb741c8ae9d5925427f6825ba73759
SHA256: 9ac0f7c55ff2ee4ca31d00f2a3d4ec30c53ab94c189f7d4228982f01893dce69
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ja.dll
executable
MD5: 9a2fc61130b68ee41476d63f415447f1
SHA256: a3a60744f7c4853eb7e44b1840a6d3def05f3bbc53dbfec0c64b0de5e8bb5e2c
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\psuser.dll
executable
MD5: 0f2166b652db61efaf7da3beebcfda65
SHA256: 2760dafa83722514e76aab3daed075750933db3d03c27d34d52b1c122f5a4113
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_sv.dll
executable
MD5: cb51bc64dc2e3f1976af760830389773
SHA256: 0eb33c5e897c3bd154e1688574a8bc4f876146306f71bc25dbd13d52b966bd3a
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_te.dll
executable
MD5: 572cd004b77c2314d1cb46465b9d4688
SHA256: 75df260b8fd23e411fbc3a5bfb968a7ff794c0aa46d566107fe2c17caddd8cfb
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ko.dll
executable
MD5: 33a88023facdd939c6c14cb692cd55e7
SHA256: 5b5feaa8f9f9621c63fdedba977c24c4a4519b3966e2d6e445a0ec9b2caa8a54
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateComRegisterShell64.exe
executable
MD5: 396ba164448844fcd0c72dd802ac7db6
SHA256: f3ada0bb7459836ba250314ea6d417694c974445f0f7218ea8a48b60c557bb89
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_sr.dll
executable
MD5: 964bdde2f1023e01412898233d72ea9d
SHA256: b8d502c1edaeb2a9250c0d3ed6ab180500be1a7e57cf20848fefc3b8048bda45
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_pt-BR.dll
executable
MD5: 87cf92508e25a76a073b0a016805f994
SHA256: e1ec02f7cc5c625d4b5dde602b66f2648c19b953ff3648867d90153f6be8c845
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_it.dll
executable
MD5: e476d68395afc1f1468ea27e7d801eab
SHA256: 44bab1dc2526c25560493fbd4d5dbb8c0cfdf53f99cbb6b9ed0ba765fb39bcab
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\npGoogleUpdate3.dll
executable
MD5: cdbe4728d075ca5050b3b9fa7138f8b8
SHA256: 051c42124192595ec6d22577e4870fad2a8ac52f04a43cb77372a99d48a9b718
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_th.dll
executable
MD5: 8b8efafaf5c073c6be9603695c66bcf2
SHA256: f143cf5135dd81fae72cc9f061b1320a059ab9a20b263d1e9612b37d029f61b7
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_tr.dll
executable
MD5: 015f150b0ad7dc922ea562e3baeb27ff
SHA256: 48a5de95d4db906a4f7ec74a1c30c9fa4311113931438c9df9c72fb8f7260e64
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_hu.dll
executable
MD5: 3b8977206e495c4c64273009e5a57f9b
SHA256: d815413523556b0d5a872c5a8a62a80bfb939e52c9d319054ef8b54a68928bdb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateHelper.msi
executable
MD5: 202b7ec9d41cda7ecc9a5db38301ab9f
SHA256: 28280e562ea8a542551505a1944f98a723f31a18b1ba69f59431245e432d2779
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ms.dll
executable
MD5: 867d3bd67091a1475a5c4fe054d82fe5
SHA256: 3cd843128bfa0053aee3c6db136e146b0671a6908e3b7c8403d262a168e81922
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_sw.dll
executable
MD5: 15a7db5d784745f4c8f06ad17c062bb0
SHA256: 51fea2ef842076e85df77fc809330805574c19cf4f9723a09ae9ce24a92591d8
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_lt.dll
executable
MD5: de7fd22ca9efb8f45842bef8b0ddd8b1
SHA256: e0bc1b946e50ad5aa24c016524da2e251530062704178ae0f51f9af02a89e1fc
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateBroker.exe
executable
MD5: 700c3948a21d47d991ef8daf7a176ae9
SHA256: d1ffd6fae6250d7f03621e54d7b8dac9882ff98e7fb2cac174c5a34a0f157bdd
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_tr.dll
executable
MD5: 015f150b0ad7dc922ea562e3baeb27ff
SHA256: 48a5de95d4db906a4f7ec74a1c30c9fa4311113931438c9df9c72fb8f7260e64
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ro.dll
executable
MD5: 427d15f9015a3a16170aa4ed86f9c8e6
SHA256: dc9b3d58d2ee1ba9eac47ef0c3e91edfb749fd6b6c7395b16f61d334f95833e1
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_id.dll
executable
MD5: 0abb138c12fdf76e83704895273ba314
SHA256: 7e676cf463cdc3f7f8ab3e41edc5dab966a86681ec4989ecc74d460cd1d56b60
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleCrashHandler.exe
executable
MD5: a2d8bef0cca959e4beb16de982e3771c
SHA256: aff4f2d3049b10893265524f4f1eeb297a60a9414f80ea3695bf1c58de2bc43d
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ru.dll
executable
MD5: af3349f27fc5996c634bcc5545108a55
SHA256: 5aac683af9938cc98996f153bdfbed7319fc08a406ef801119e3a64f77ec6942
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_sl.dll
executable
MD5: c337b1203f9293549ba29e5be5dcccff
SHA256: e2991885badc9d7f2737e61fc6421e80b7adcd6e9dab439728200333393f9a55
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_lv.dll
executable
MD5: bcc3f87f93fa8c9ff8efbca84abd4f20
SHA256: fc52bcaa4081a8bf597b6cdca4981c9b29b59bac40f8307fa334a3485d2009d9
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdate.dll
executable
MD5: 69d1bf5384cea587e6cc69ac827cc02d
SHA256: d8f9c6a2e3f784e4a9c9dd714e1fbfea1883b920216dc01ad9d56700b17c0671
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_pt-BR.dll
executable
MD5: 87cf92508e25a76a073b0a016805f994
SHA256: e1ec02f7cc5c625d4b5dde602b66f2648c19b953ff3648867d90153f6be8c845
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_vi.dll
executable
MD5: 9660f97192873e3aafb6e1fb0277a2e6
SHA256: 0dc040171aca029892b70963216071ca51caa5c3dc4d6372eb447414b0a00689
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_kn.dll
executable
MD5: 072f51e42208a3d311105ef2fd72a883
SHA256: 77d6d93944a212f7efb2455f46db20277e0a5a4fada9a04a0d7392c5aa30cc22
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdate.exe
executable
MD5: 82f657b0aee67a6a560321cf0927f9f7
SHA256: 794cf7644115198db451431bca7c89ff9a97550482b1e3f7f13eb7aca6120a11
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ro.dll
executable
MD5: 427d15f9015a3a16170aa4ed86f9c8e6
SHA256: dc9b3d58d2ee1ba9eac47ef0c3e91edfb749fd6b6c7395b16f61d334f95833e1
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ta.dll
executable
MD5: 36c0dee9d410cef6dd3178d7fc405810
SHA256: 0df14319ce6648a457185c5214eda3595da1001cd495d90743498435ff1348ee
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_iw.dll
executable
MD5: 0da881f72338a4fb295a3fb837a696e5
SHA256: 8c7a9d6f96d007d9557eea5009ce20b7d1be0334aa7d8168d79c9867a733a932
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
C:\Users\admin\AppData\Local\Google\libs\node.exe
executable
MD5: d382a1b552edeed2d33bdd7559ee8100
SHA256: 8cc341dc3aeb510d5dfbd6595dfd8ca60852e5d0f06a2548cda14faacd7eb043
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_zh-CN.dll
executable
MD5: 0ffb741c8ae9d5925427f6825ba73759
SHA256: 9ac0f7c55ff2ee4ca31d00f2a3d4ec30c53ab94c189f7d4228982f01893dce69
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_th.dll
executable
MD5: 8b8efafaf5c073c6be9603695c66bcf2
SHA256: f143cf5135dd81fae72cc9f061b1320a059ab9a20b263d1e9612b37d029f61b7
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_hi.dll
executable
MD5: a5a40fde77ce0330572603819f7eab1a
SHA256: 1e19516dacf3e895e632cfa6e863d4896a5847281602c16cf3995c107860888e
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
C:\Users\admin\AppData\Local\Google\CCLibrary.exe
executable
MD5: 5b85733a6a08ad0bbf1eaba4a2fd6bc7
SHA256: b335c25ff12d1ac94d6d2138fe4c83b59c95bef11b14ec62ad79943c43d16999
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_te.dll
executable
MD5: 572cd004b77c2314d1cb46465b9d4688
SHA256: 75df260b8fd23e411fbc3a5bfb968a7ff794c0aa46d566107fe2c17caddd8cfb
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_ms.dll
executable
MD5: 867d3bd67091a1475a5c4fe054d82fe5
SHA256: 3cd843128bfa0053aee3c6db136e146b0671a6908e3b7c8403d262a168e81922
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_mr.dll
executable
MD5: 28d4751e027905c336b515ae1f3aa180
SHA256: 3c7a123cd8bf4515b7289692571de55f2b40c5fe6962b748e276af3906199442
748
setup.exe
C:\Program Files\Google\Chrome\Application\chrome_proxy.exe
executable
MD5: ff015999e4d534cb6783740abbdee63c
SHA256: 6950c3d16fdcd66e7228536995c685b7ec844eac4465780ea6913834e0774e00
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ml.dll
executable
MD5: c75102b45b2086b3508b6c1258ddb604
SHA256: 8dd0d64d6883c721087e0f58b5c195893f0fb2451468fe5eccc7a9f44f3d1537
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_is.dll
executable
MD5: 4c954e97257e899d5941e190fcef8ca9
SHA256: c14d1ce67e2a671feb5cfab3176cb0c73b31585ba32d40d9f21b1a892c1b2e20
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_uk.dll
executable
MD5: 1704be0e60765c931b5a2aed62ed2ed3
SHA256: b8027ca5e88df6fbf11705cc312a63d5659d2abb0d826dcc21255b72efbfc681
748
setup.exe
C:\Program Files\Google\Chrome\Temp\scoped_dir748_9470241\chrome_proxy.exe
executable
MD5: ff015999e4d534cb6783740abbdee63c
SHA256: 6950c3d16fdcd66e7228536995c685b7ec844eac4465780ea6913834e0774e00
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_vi.dll
executable
MD5: 9660f97192873e3aafb6e1fb0277a2e6
SHA256: 0dc040171aca029892b70963216071ca51caa5c3dc4d6372eb447414b0a00689
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_nl.dll
executable
MD5: 215ca7776e35f174224c07596b91ef73
SHA256: a2264b70bf36805f4ce1c9faabb52863f445d4ec30bb9b0517f6c24f94c833d0
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_pt-PT.dll
executable
MD5: 5a45a26a54f413fc9ae3010432ac28cf
SHA256: d2ed2b685d8c5352cca042ec2df9c9ac9b3dc1129d3e0a4c09c31956cd0ae105
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
C:\Users\admin\AppData\Local\Google\js\addon.node
executable
MD5: cc0eac2a0699ba4a9d6c693d26d880a2
SHA256: dc425050c4bdb45f425ab9194519d18ab71877a59dfcc7094acc44ee46025572
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_sl.dll
executable
MD5: c337b1203f9293549ba29e5be5dcccff
SHA256: e2991885badc9d7f2737e61fc6421e80b7adcd6e9dab439728200333393f9a55
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\goopdateres_mr.dll
executable
MD5: 28d4751e027905c336b515ae1f3aa180
SHA256: 3c7a123cd8bf4515b7289692571de55f2b40c5fe6962b748e276af3906199442
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_hr.dll
executable
MD5: 41b96846b3e594d215e049bc6e44e7d5
SHA256: f53fa99736059d03ca35499f15d39be942d6f3633d47942e98a79d423aeccacd
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_nl.dll
executable
MD5: 215ca7776e35f174224c07596b91ef73
SHA256: a2264b70bf36805f4ce1c9faabb52863f445d4ec30bb9b0517f6c24f94c833d0
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_ur.dll
executable
MD5: 002e1990162182adc8b81a7e5f1a85e5
SHA256: 8d476b5e01268c462d994c0799ea4bdd01cbeeefeb546eacc8b51e2c1ddda438
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\goopdateres_es-419.dll
executable
MD5: babcc3d7ac72bb5fcbf504b960b7a233
SHA256: fce66f6407d801d0a8b6d47c7286622cb5d800d7520f5c14ac162fa3145dbfc1
956
GoogleUpdateSetup.exe
C:\Program Files\GUMBC94.tmp\GoogleUpdateOnDemand.exe
executable
MD5: 597cb67524c8e93909696845d60a1647
SHA256: 68f5e571fa04f07b33b82c2f7e4354dec80f037ccf419722c26fe091f649ad39
1188
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\GUMB456.tmp\GoogleUpdateSetup.exe
executable
MD5: 8a401f5047e3012b8c53905a08973089
SHA256: b3def08dbad77219d673e9f50d990593ceeaf2e9124356eb2b329a893daf7bb4
3004
CCLibrary.exe
C:\Users\admin\AppData\Local\Temp\CreativeCloud\Creative Cloud Libraries\CC Library Process.log
text
MD5: b3ac8b4ccf7f62d7a424f86dd5e4edbc
SHA256: 488aa0e5db578b5a75f08e14df3fb74ce92b00e410471370a030d9f20e83cf45
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\da.pak
mmw
MD5: 3196ab4a28de6781157574f256bf121d
SHA256: 8b8ddf5cee6f9718e962af1e30880b0fe15547c429a369597b3d3cf4d577cbd5
2588
msiexec.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
4088
GoogleUpdate.exe
C:\Program Files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\78.0.3904.108\78.0.3904.108_chrome_installer.exe
––
MD5:  ––
SHA256:  ––
4088
GoogleUpdate.exe
C:\Program Files\Google\Update\Install\{314126C4-A428-4096-98CD-D51F3B136C18}\78.0.3904.108_chrome_installer.exe
––
MD5:  ––
SHA256:  ––
4088
GoogleUpdate.exe
C:\Users\admin\AppData\Local\Temp\gui6C4C.tmp
text
MD5: 959b2470a0596a090751fb5842f7749c
SHA256: 9a1cdce548a0cf3ee00b3dec5964c7ba3a3d5312f0d051395bc1cd6a50c9395b
3176
78.0.3904.108_chrome_installer.exe
C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\CHROME.PACKED.7Z
––
MD5:  ––
SHA256:  ––
3176
78.0.3904.108_chrome_installer.exe
C:\Users\admin\AppData\Local\Temp\CR_9F57A.tmp\SETUP.EX_
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Windows\TEMP\Crashpad\settings.dat
binary
MD5: bc57d688a656ce287955db827ac8b5d0
SHA256: 1e1ee50e985d6de9f098866ac6ba704c30a94bd5df4af6d92b7315833f4f23f3
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\chrome.7z
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\3155e47b-3129-41dd-86ba-b128b8bcbe1f.tmp
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\78.0.3904.108.manifest
text
MD5: 4ea254c749a60a9e062b10d84e13b728
SHA256: 42e61e5db7fcb76d4d25d45d7a72eedce60ab8a06f14896c6379837f47f963e9
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\chrome_200_percent.pak
pgc
MD5: 04dbbed4bf44dd90f5a8691a27e8d231
SHA256: cecd2dfe95184eb2d3b4806fcd7ea23343ffe022de8ab683b604cd4948135665
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\chrome_100_percent.pak
pgc
MD5: 60c57f4065be6677ef9b347d8c67d4bc
SHA256: b43ca663d92dbc455cc100c804bc92af744111dc84f4a6cf3498ca74f01673b6
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\default_apps\external_extensions.json
text
MD5: 19b3ace22f537241581cd52a49ee90ce
SHA256: b12cda916b67bb71b772df84e9f84fd33a3e6f8c9b840a0888b96eee095b9dd9
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\default_apps\docs.crx
crx
MD5: 2c71c49f991095a1848624907bacbb08
SHA256: 530a1e894fddafbd8a67c68aba1d4c6cfab35e381929eb47dbcaf1a2c70c2774
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\default_apps\gmail.crx
crx
MD5: 2e2e328e5bf6be61203164b3e9ea8094
SHA256: 12ce071e7f5931478ae91161391763a52b8c01a4441fe44a52ad8250b13f8f20
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\default_apps\drive.crx
crx
MD5: 71e1283b8440f6264cec99df9ad81f5b
SHA256: a8ffd941dbee29103c0cc921e0cc74b08ad6725447bb6d1cde221284776b2559
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Extensions\external_extensions.json
text
MD5: 280a9277b0e605e905d7f18b6148eeb7
SHA256: a68cafd7d78d5c671c2560656653f2a4d83ab66d87a8728356a88fb1f477b3e6
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\default_apps\youtube.crx
crx
MD5: d2f6a1b11344d9ac7bcfb75900d4ade1
SHA256: c090f4ac26727e368b83413cf791079024c3aa99c410113dc20015b7cf491d99
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\icudtl.dat
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\am.pak
pgc
MD5: 2b6d52d7e2da3836dc23364c277d8bf3
SHA256: 30a796b7f63a40b5ece42999a6428a26887aa05ba911ed53185ddb138d709a83
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\bg.pak
pgc
MD5: 812498a5f3950d1f271540e277dfc414
SHA256: 786864c49e601985b95f0864336a65c228b029068d4e3cdfa333bf7a3c3b0826
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\ar.pak
mmw
MD5: f2901919da5feafdb9b05e51c65c3d1c
SHA256: 7a880e9ebd4180646836fab435d31371dcbb07e91e7cf3319924ba888e36b91d
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\es-419.pak
mmw
MD5: d27526182c8807cf7e411ac339bb4e81
SHA256: 815a576e9c43a3ba079df6ef1168041eed91110c0434932d0aa2854ab85947d4
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\bn.pak
pgc
MD5: 767faa8826ab60c7cabff54f13557b09
SHA256: 6d53c106dc1b10d967d675844421faa578db27e3ecbaa07a290804977615a63b
748
setup.exe
C:\Program Files\Google\Chrome\Application\SetupMetrics\20191203004705.pma
binary
MD5: 1dfed45b842e40eb3320733399e7b122
SHA256: 4a5167d894924d636025aaa6622cdaf9ab5c621a5346fa87917ca0814f0db1ee
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\de.pak
mmw
MD5: 27a3275d3085cd1953ea29a9f244c732
SHA256: 68958925fddd97943df701db13e8c46fa0795b6e796e2ece6ef0b06176955e9e
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\en-GB.pak
mmw
MD5: c216d0185d81b169434ca406902125cc
SHA256: 895fe9cb56a187d66fda7d6195b46d10dd4561819b9bde92cb4e94dbd5388c0b
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\en-US.pak
mmw
MD5: e7ebb441fd3a98615b891ba0174c3e37
SHA256: ea3de19daa27427e5a8adc5581bd81bcf971d3635186d4f6d630d99c22a638c3
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\et.pak
mmw
MD5: 820142cf7856c50559fd2a03fc8e009c
SHA256: 1d4206650ceca99c31e128aa5d6923977ebe8d1448b37ef29740c43ed84bd1d6
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\es.pak
mmw
MD5: b2966af4cf43d4f3f4ccec84ffc801c9
SHA256: 73c53461eddb2bf78b61c9ca58c06726c02d0cf21a04e81116f9ba7c90dc0821
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\ca.pak
mmw
MD5: d6f124439bc632b582f212caa2c512ab
SHA256: 99232201f2225bd1ff33ed46d19460452e8f72e8cd9093e5b7e61981fea2276a
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\el.pak
pgc
MD5: a4f4d35bc8d92ff17261236b499f13f1
SHA256: 3e18da6e4b457bee08c78bae4c05ef440f9811208d6e36cf487d8bde3de3d664
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\cs.pak
mmw
MD5: 6301061703d839a886a8642984bb1f8a
SHA256: 433b7e971225f5219f04dc4054330be1c8e1ace19d1043f7e870d93d2fce917e
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\fr.pak
mmw
MD5: bf0edb61b6939046743a96d0d084dedb
SHA256: a6b3184a0aca2289e2d58a4fc09607ba4b1811377e5f391630288bdeca5e0c93
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\hi.pak
pgc
MD5: cc0cca26a2bfa9066b9a6c331e32afc2
SHA256: 80b75998e824ca69f3e66abdfade8c2ee25b9f6ce072c5a874d1bfbefede5e07
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\fil.pak
mmw
MD5: d04715547d069dfed7f440bf0a7c2bde
SHA256: fea45dc6255c2757f691db9dae7bc2ea53a5d9da21e3e3f5f4c100953108519e
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\hr.pak
mmw
MD5: 340a587e2f3d21accb7302e4e32ca37b
SHA256: 49dfb01f1d54b5274159f61621194572a91cf5931c514b82b13f89f03262aff5
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\he.pak
pgc
MD5: db512cfadfe1bb8d138ae9639c082ab5
SHA256: 98eca54da32a05eb447e42800ef1818cabc07aeba715593a74aa83b02ef4936e
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\fi.pak
mmw
MD5: 0bda51eec32b4853a64ab3b9e2c3bf72
SHA256: 50fd0bd6f8e963c2ba5e0ef27d04939849cb6d81ec21ce9e2b952ab8aaeb04d9
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\fa.pak
pgc
MD5: 9eba736d7c1a40bfb7863b74170ffc03
SHA256: d40265b5831665b3e8371ca011c0393a0c07234b1f04a9303cd762cd7dd8c394
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\gu.pak
pgc
MD5: 9751fd904251e50df5b52147c8efad4a
SHA256: 13671b0ffb490f71176502698d70b857178fc453668dbc02416453be0450dea0
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\hu.pak
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\it.pak
mmw
MD5: d757aafbc4bffb1e7283f383713dde4e
SHA256: 19189be311cbea058f28c4772196ed9886b4b42d731011208f94301448bc048e
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\ja.pak
pgc
MD5: a9e2200ebdda6525e818c1b6123b2b16
SHA256: b1dd908fa6631128ddbad66cde1bb6e209930e8a4145ff1f9712482eb582639a
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\Locales\id.pak
mmw
MD5: c2e8f8162bc051f2a29ca47cb9dd7f8f
SHA256: 8b80a5c6cf101232b5aa1661462e40b806d9191223c1e41f3915a575f9ad47d5
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\chrome.dll
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Program Files\Google\Chrome\Temp\source748_1890252937\Chrome-bin\78.0.3904.108\chrome_child.dll
––
MD5:  ––
SHA256:  ––
748
setup.exe
C:\Program Files\Google\Chrome\Application\SetupMetrics\dea8296b-4060-400a-aab7-9e7f695b9123.tmp
––
MD5:  ––
SHA256:  ––
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
C:\Users\admin\AppData\Local\Google\js\server.js
text
MD5: 619a9ad05d423ec656c6a41190e141a7
SHA256: 1fdc9a0d472146efb325234f792b4881a9e871b96c3fac5d104479c872ec6b26
2952
d2ee013fdf1f7aad62315d4c27de5c88.exe
C:\Users\admin\AppData\Local\Google\node.ax
binary
MD5: d965f7add4922cf9a172a7bfbfd41daa
SHA256: 2a6ac60408bad9e05f4b52fecfbcfd8ffdfd6efe51173869e90ac95e790d14b2
748
setup.exe
C:\Users\admin\AppData\Local\Temp\chrome_installer.log
text
MD5: 6c081de202c3e4daf57618240ae93e12
SHA256: 55da0d711a3fc227cd308cb8eaa6251e5a4d6763852792073f70446afd901b2b

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
6
DNS requests
4
Threats
2

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2588 msiexec.exe GET –– 27.255.94.85:80 http://onedrive.live.com/logo32x32.gif KR
––
––
unknown
–– –– HEAD 200 195.95.178.206:80 http://r3---sn-pouxga5o-vu2l.gvt1.com/edgedl/release2/chrome/APn1pwO9VALScz7ut0kK-RU_78.0.3904.108/78.0.3904.108_chrome_installer.exe?cms_redirect=yes&mip=85.203.45.39&mm=28&mn=sn-pouxga5o-vu2l&ms=nvh&mt=1575333920&mv=m&mvi=2&pl=26&shardbypass=yes RO
––
––
whitelisted
–– –– GET 200 195.95.178.206:80 http://r3---sn-pouxga5o-vu2l.gvt1.com/edgedl/release2/chrome/APn1pwO9VALScz7ut0kK-RU_78.0.3904.108/78.0.3904.108_chrome_installer.exe?cms_redirect=yes&mip=85.203.45.39&mm=28&mn=sn-pouxga5o-vu2l&ms=nvh&mt=1575333920&mv=m&mvi=2&pl=26&shardbypass=yes RO
executable
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2588 msiexec.exe 27.255.94.85:80 Korea Telecom KR unknown
3640 GoogleUpdate.exe 172.217.22.67:443 Google Inc. US whitelisted
4088 GoogleUpdate.exe 172.217.22.67:443 Google Inc. US whitelisted
–– –– 172.217.18.174:80 Google Inc. US whitelisted
–– –– 195.95.178.206:80 Asociatia Interlan RO whitelisted

DNS requests

Domain IP Reputation
f0x.co 27.255.94.85
unknown
update.googleapis.com 172.217.22.67
whitelisted
redirector.gvt1.com 172.217.18.174
whitelisted
r3---sn-pouxga5o-vu2l.gvt1.com 195.95.178.206
whitelisted

Threats

PID Process Class Message
–– –– Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP
–– –– Misc activity ET INFO EXE - Served Attached HTTP

Debug output strings

No debug info.