General Info

File name

VC2008.EXE

Full analysis
https://app.any.run/tasks/4c1da05c-a5de-421c-89d3-9bb6d951523e
Verdict
Malicious activity
Analysis date
8/13/2019, 18:06:59
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

b936f0f378b9a35489353e878154e899

SHA1

56719288ab6514c07ac2088119d8a87056eeb94a

SHA256

c6a7e484f4d84883bc1205bccea3114c0521025712922298ede9b2a1cd632357

SSDEEP

49152:wQixbpVndRcpfqwYO3u2XoKNLlMDEe/pmVS/F0jD:wtdnfnwp3oOLuB/3/uD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • install.exe (PID: 4092)
Loads dropped or rewritten executable
  • install.exe (PID: 4092)
Removes files from Windows directory
  • msiexec.exe (PID: 3888)
Creates files in the Windows directory
  • msiexec.exe (PID: 3888)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 3888)
  • VC2008.EXE (PID: 2852)
Creates a software uninstall entry
  • msiexec.exe (PID: 3888)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   MS generic-sfx Cabinet File Unpacker (32/64bit MSCFU) (82.5%)
.exe
|   Win32 Executable MS Visual C++ (generic) (7.3%)
.exe
|   Win64 Executable (generic) (6.5%)
.dll
|   Win32 Dynamic Link Library (generic) (1.5%)
.exe
|   Win32 Executable (generic) (1%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2005:06:01 18:46:51+02:00
PEType:
PE32
LinkerVersion:
7.1
CodeSize:
31232
InitializedDataSize:
6144
UninitializedDataSize:
null
EntryPoint:
0x5972
OSVersion:
5.2
ImageVersion:
5.2
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
9.0.21022.8
ProductVersionNumber:
9.0.21022.8
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
Microsoft Visual C++ 2008 Redistributable Setup
FileVersion:
9.0.21022.08
InternalName:
vcredist_x86.exe
LegalCopyright:
© Microsoft Corporation. All rights reserved.
OriginalFileName:
vcredist_x86.exe
ProductName:
Microsoft Visual C++ 2008 Redistributable
ProductVersion:
9.0.21022.08
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
01-Jun-2005 16:46:51
Detected languages
English - United States
Debug artifacts
db
CompanyName:
null
FileDescription:
sfxcab
FileVersion:
6, 1, 22, 5
InternalName:
sfxcab
LegalCopyright:
Copyright (C) 2006
OriginalFilename:
sfxcab.exe
ProductName:
sfxcab
ProductVersion:
6, 1, 22, 5
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
3
Time date stamp:
01-Jun-2005 16:46:51
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00002000 0x000078A0 0x00007A00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.58359
.data 0x0000A000 0x000110D4 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0.509584
.rsrc 0x0001C000 0x00001474 0x001B2600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.99914
Resources
1

100

101

107

Imports
    KERNEL32.dll

    msvcrt.dll

    ADVAPI32.dll

    USER32.dll

    ntdll.dll

    COMCTL32.dll

    SHELL32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
40
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

+
drop and start start vc2008.exe no specs vc2008.exe install.exe no specs msiexec.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3020
CMD
"C:\Users\admin\AppData\Local\Temp\VC2008.EXE"
Path
C:\Users\admin\AppData\Local\Temp\VC2008.EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2008 Redistributable Setup
Version
9.0.21022.08
Modules
Image
c:\users\admin\appdata\local\temp\vc2008.exe
c:\systemroot\system32\ntdll.dll

PID
2852
CMD
"C:\Users\admin\AppData\Local\Temp\VC2008.EXE"
Path
C:\Users\admin\AppData\Local\Temp\VC2008.EXE
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2008 Redistributable Setup
Version
9.0.21022.08
Modules
Image
c:\users\admin\appdata\local\temp\vc2008.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\feclient.dll
c:\windows\system32\apphelp.dll
c:\068db81b0192cc457d10422414c14f\install.exe

PID
4092
CMD
c:\068db81b0192cc457d10422414c14f\.\install.exe
Path
c:\068db81b0192cc457d10422414c14f\install.exe
Indicators
No indicators
Parent process
VC2008.EXE
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
External Installer
Version
9.0.21022.8 built by: RTM
Modules
Image
c:\068db81b0192cc457d10422414c14f\install.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\devobj.dll
c:\068db81b0192cc457d10422414c14f\install.res.1033.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\updater.exe
c:\windows\system32\secur32.dll
c:\windows\system32\msi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\riched20.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\vc\msdia90.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll

PID
3888
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\vc\msdia90.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\sxsstore.dll

Registry activity

Total events
448
Read events
244
Write events
198
Delete events
6

Modification events

PID
Process
Operation
Key
Name
Value
4092
install.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3888
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
3888
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72
3888
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3888
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3888
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3888
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3888
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3888
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
300F00007CE55C31F151D501
3888
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
8375303808DFE5374C72D217E055E8437DE4222A0A142B93AAA1A949B3F95607
3888
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
c:\Windows\Installer\37c990.ipi
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
c:\Config.Msi\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
c:\Config.Msi\37c991.rbs
30757369
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
c:\Config.Msi\37c991.rbsLow
2505305776
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA5D9C68C00F12943B2F6CA09FE28244
6F9E66FF7E38E3A3FA41D89E8A906A4A
02:\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\SP
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DDA695F96EBE974FAAE0D63A6F7BE67
6F9E66FF7E38E3A3FA41D89E8A906A4A
02:\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033\Install
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
c:\Program Files\Common Files\Microsoft Shared\VC\msdia90.dll
2
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206
6F9E66FF7E38E3A3FA41D89E8A906A4A
c?\Program Files\Common Files\Microsoft Shared\VC\msdia90.dll
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\62F506F212036F83CA1371C5D0AF959B
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F0F3C67D9B9AD53186CACA888CC39AC
6F9E66FF7E38E3A3FA41D89E8A906A4A
>atl90.dll\Microsoft.VC90.ATL,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97513DBDA020E943E86D0DF6AE57FA54
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\79362268BD320343C8A8EA6A161BEA77
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\25ECC26A083C1113ABD7D3E0FD3A2131
6F9E66FF7E38E3A3FA41D89E8A906A4A
>\policy.9.0.Microsoft.VC90.ATL,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311DCF2CAC53720329DC2F6D6472C71A
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EFE09CEA8B938793A8D560F8FE382D57
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27BE807B28AA7BE3B80B8D54AB539CD3
6F9E66FF7E38E3A3FA41D89E8A906A4A
>msvcr90.dll\Microsoft.VC90.CRT,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B651C5A13CC33E63AB7DF90D4D18653D
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD2E7D865CB5C813FA91911D2DE96D29
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D26B2F41F5FDF5335A7190194FC40B78
6F9E66FF7E38E3A3FA41D89E8A906A4A
>\policy.9.0.Microsoft.VC90.CRT,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0D5F5530C7649E0398C42CAFFE25A211
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80FBC10D4B028C03FAA5699F48E7283A
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55C7536C164715D3A95EDF17AC4220A7
6F9E66FF7E38E3A3FA41D89E8A906A4A
>mfc90.dll\Microsoft.VC90.MFC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C188116F2EBE3930AF4186CD30F8015
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFB76F51AA6DB8C31ABB3CE3719E526C
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CD2BBFB687F47123CAFCDC82838A6412
6F9E66FF7E38E3A3FA41D89E8A906A4A
>\policy.9.0.Microsoft.VC90.MFC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B35AE21A043D5F31BCBA4B3CEA4987A
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC1E60A59C989BD3B98CB5AF655BB8BF
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A175F2FF45C63E132BE3A20682B3808A
6F9E66FF7E38E3A3FA41D89E8A906A4A
>mfc90cht.dll\Microsoft.VC90.MFCLOC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F04C2F9CDC82C2930A3CA3DACE31C0A0
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC2108D4EC2B3943198B8B9A9B286F8B
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0D8ABEF022D5A3D349D755E992FB70FD
6F9E66FF7E38E3A3FA41D89E8A906A4A
>\policy.9.0.Microsoft.VC90.MFCLOC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64C620F6CB6D50833A0B11A78F749382
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA35D58AD6095C13693E2EB19B51E4C2
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3F4F115D119AFC23CA11C979FE49B8CF
6F9E66FF7E38E3A3FA41D89E8A906A4A
>vcomp90.dll\Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CF68F61B49DBAF0389AA71BA5EF44087
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C01B6B82F14EB2036A37104F63245722
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75EC17D83CDB0B43DADAAEC4A5CF6946
6F9E66FF7E38E3A3FA41D89E8A906A4A
>\policy.9.0.Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A891A946D91CF523FBA37CAE6EF2E56F
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE57BB6B8E2E3848AA4773134975546
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D72CFC1B540B9014C983F2B89EC0AD3A
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9139CDB10A2211C458036000CA13F613
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\298095F840DB82A4C997E3EE402B0B0D
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC1BF68872161FB4C94C84F195523AB7
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCCD3CF96BADF7E42A9468F29E623555
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D44BDE8068B242B43963888890D3BA9B
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97486C5D001A175448A3E30BF3B775B3
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFB8A0EA52A3591408D6120D165BAF11
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A82B8DA21FCE4542840AD18154B6003
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3FFF22A42C37CBB4DA2CC697237A99B9
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\303FD3DF888283041A37A5688745D217
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8267078178EFD2D43874621BFF124618
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB9303D405CDB134CB30CD367AC97F2B
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C131C196F822F5418614A704F514399
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5E445F6BDBA2B346B9FC57B7169F65B
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCB893E3BCA189C4B96FA7F49DC89DA5
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CC3911F7FC23D948BF67404DA99F113
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81E5FA91DB0274CBFA0C024E748E82
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA0CEFB36BB0E664381F5BCC75524D33
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53714D3915F0E734D9809C232714222E
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8477A35EABCAFE040A730AE47C57DEA2
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\614A75AA111769C4BB8A6B8F035000B0
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1546C7E77B0CE34EADB0FEAE4DB0BC7
6F9E66FF7E38E3A3FA41D89E8A906A4A
c:\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
PatchGUID
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
MediaCabinet
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
File
FL_msdia71_dll_2_60035_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
ComponentVersion
9.0.21022.8
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
ProductVersion
9.0.21022
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
PatchSize
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
PatchAttributes
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
PatchSequence
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
SharedComponent
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\6F9E66FF7E38E3A3FA41D89E8A906A4A
IsFullFile
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0
SP
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0
SPIndex
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
Install
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
InstallerType
MSI
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
SP
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
SPIndex
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
SPName
RTM
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
LocalPackage
c:\Windows\Installer\37c992.msi
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
AuthorizedCDFPrefix
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Comments
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Contact
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
DisplayVersion
9.0.21022
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
HelpLink
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
HelpTelephone
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
InstallDate
20190813
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
InstallLocation
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
InstallSource
c:\068db81b0192cc457d10422414c14f\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
ModifyPath
MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
NoModify
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
NoRepair
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Publisher
Microsoft Corporation
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Readme
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Size
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
EstimatedSize
1456
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
UninstallString
MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
URLInfoAbout
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
URLUpdateInfo
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
VersionMajor
9
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
VersionMinor
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
WindowsInstaller
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Version
151015966
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
Language
1033
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
AuthorizedCDFPrefix
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Comments
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Contact
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
DisplayVersion
9.0.21022
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
HelpLink
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
HelpTelephone
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
InstallDate
20190813
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
InstallLocation
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
InstallSource
c:\068db81b0192cc457d10422414c14f\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
ModifyPath
MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
NoModify
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
NoRepair
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Publisher
Microsoft Corporation
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Readme
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Size
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
EstimatedSize
1456
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
UninstallString
MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
URLInfoAbout
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
URLUpdateInfo
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
VersionMajor
9
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
VersionMinor
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
WindowsInstaller
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Version
151015966
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Language
1033
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\41A387AA3A7A33D3590FA953D1350011
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\InstallProperties
DisplayName
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
DisplayName
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.ATL,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_ATL_x86>JpU2NrV7B5qy_[T,(4,j
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.ATL,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_ATL_x86>r$fJ^YCTj3V9%Y'}*'.)
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.CRT,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_CRT_x86>FBBocKWG18(q-N=uYwq7
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.CRT,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_CRT_x86>ic?g)O&RS4%q5]VLQr[S
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.MFC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_MFC_x86>K0qdh3C0e7n!._L=H.6O
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.MFC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_MFC_x86>uL}dJ5hL+4E+f,1qJ(d-
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.MFCLOC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_MFCLOC_x86>tMG${S*u%4NG-vF8PN!_
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.MFCLOC,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_MFCLOC_x86>G4x,(urbb7)6StZMvxbp
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_OpenMP_x86>MOpPm6x+D4pamfX1o92z
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
pUA*{b52f6dJF(t{O$w]FT_VC_Redist_OpenMP_x86>M9,[email protected]{0!DH
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
VC_RED_enu_x86_net_SETUP
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
VC_RED_enu_x86_net_SETUP
5`c]JiaZ6?P)l9)Iv!9H?A]0bijiu8c(GgTG19a]x^0z+HQ([email protected]!!QmQt3Vi+)V]Gyo?lwWXuam3)[email protected]@FE`'-qt^gO1P[E[-!T7Au(C?32=}KCv~vr%I&[email protected]{usS$s=bdn?,em&$.C=&-j_avj0)7i,]x`_Q`)9^=utkKv2k((]$k`H2K?=a9JgQeu$M3.CDo?gE%[email protected]$G4%[email protected]_8taH3S=1sGLO``q*[email protected]}Txa*znYQE[[email protected]_nDX9!4'+Hmt3TbtkqpV%tpP=l.hN%[email protected]?xcPF^BcLWv~7HiO]@*hBVAnsv4E.PVQvj9nf?(j%a8ko~k3-*qFagQ.r=v4jT-f4V01!'[email protected]](_=v}OljWfu`4-JSSWJWnc9unIC42cfbq^[=brkm}r8DW{=[email protected]]@80YxxiESU&7ynQs+5Wo90037abAJ)P
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
Servicing_Key
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
Servicing_Key
N~=CS6YuR?JaKO&hd{u98h5xw2NY$?uhS]5u_i6N
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
VC_Redist_12222_x86_enu
]$i8f{cUCAL6PArlXIvF
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
FT_VC_Redist_ATL_x86
VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
FT_VC_Redist_ATL_x86
90?73S&.B6z.nZECjZXdJpU2NrV7B5qy_[T,(4,jguF`o]iMv4y)cxK!sfI=w.J,S23fj4?nWX^b5ZONr$fJ^YCTj3V9%Y'}*'.)xlpag%iQP3R*1*n_7Zu[VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
FT_VC_Redist_CRT_x86
VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
FT_VC_Redist_CRT_x86
X4y2awX!P6Pu?{U5xjrMFBBocKWG18(q-N=uYwq7u$-P+BxO_5&yH'lS'Twl&?5dI]E[w3,pC5lX8O4Wic?g)O&RS4%q5]VLQr[SG&.)$Z(5f3gxNZyPexS(VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
FT_VC_Redist_MFC_x86
VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
FT_VC_Redist_MFC_x86
-mItkKIab3n6N6yQzuV]K0qdh3C0e7n!._L=H.6OAYV5G42sI6axxlhZak&BX$!(*rl'O7-$a28kr3chuL}dJ5hL+4E+f,1qJ(d-(Lh))X+&G8r2l'77'vp^VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
FT_VC_Redist_MFCLOC_x86
VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
FT_VC_Redist_MFCLOC_x86
3{LxDsL9p74'TOygrypytMG${S*u%4NG-vF8PN!_dG!vi)[tG6uGMb`=]P7&'[email protected]%P[V_jU}MdG4x,(urbb7)6StZMvxbpLh`bKNuP!6^Il7Ounrw0VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\6F9E66FF7E38E3A3FA41D89E8A906A4A
FT_VC_Redist_OpenMP_x86
VC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Features
FT_VC_Redist_OpenMP_x86
'FU,_s8e~3Kvnz+ryF82MOpPm6x+D4pamfX1o92zxIE%bPQ(h3)m'~_*pfXNpH9*1-6~P34&{Kw47F).M9,[email protected]{0!DHvIDDHos144%{sNt=LR3xVC_Redist_12222_x86_enu
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\Patches
AllPatches
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
ProductName
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
PackageCode
F37207D363F3FBE43901D6914195B624
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
Language
1033
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
Version
151015966
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
Assignment
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
AdvertiseFlags
388
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
InstanceType
0
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
AuthorizedLUAApp
1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
DeploymentFlags
3
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\41A387AA3A7A33D3590FA953D1350011
6F9E66FF7E38E3A3FA41D89E8A906A4A
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\SourceList
PackageName
vc_red.msi
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\SourceList\Net
1
c:\068db81b0192cc457d10422414c14f\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\SourceList\Media
DiskPrompt
[1]
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\SourceList\Media
1
;1
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A
Clients
:
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\SourceList
LastUsedSource
n;1;c:\068db81b0192cc457d10422414c14f\
3888
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
115

Files activity

Executable files
44
Suspicious files
4
Text files
38
Unknown types
10

Dropped files

PID
Process
Filename
Type
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\vc_red.msi
executable
MD5: e0951d3cb1038eb2d2b2b2f336e1ab32
SHA256: 507ac60e145057764f13cf1ad5366a7e15ddc0da5cc22216f69e3482697d5e88
3888
msiexec.exe
C:\install.res.1031.dll
executable
MD5: 3b8a82e04238655eaef97e074fb29911
SHA256: 5e49c21b9a15c3a0fddde7ddc32fda220302ee57b8aff66f4f78b370e049410d
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90fra.dll
executable
MD5: 07f20e09c028f0e5469ca8eb782724de
SHA256: 996e42ddbeba26f92f33338ccc8e3b2fac91d70ded4c311c7a64c6850a7b2f0e
3888
msiexec.exe
C:\Windows\Installer\37c98e.msi
executable
MD5: e0951d3cb1038eb2d2b2b2f336e1ab32
SHA256: 507ac60e145057764f13cf1ad5366a7e15ddc0da5cc22216f69e3482697d5e88
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90esp.dll
executable
MD5: eeb0a4cc976a8d732eb1168514c77236
SHA256: a7fe95e7fc7420a12a71d9aee57130adefd3afc3017eb98bcfcb509b2f2af1bf
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90esn.dll
executable
MD5: 9bff4f740c98ea1d881d94512b08013c
SHA256: 6af004041fdfc158616dcc40a26853ac82f0d70f03fb4eed2e15fffab01551cf
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90kor.dll
executable
MD5: 5017f29e77552c1a34cd4d835362cdd7
SHA256: 3baec8e203787cca2c7e6d106d92859be6496e03ad70318167ff729472814b3d
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1036.dll
executable
MD5: 5b6ff470cfa7087690e61f87e81ef78a
SHA256: 2d1c0a1b17266cff3be7d46cf3020b176e4a058fd7fc57f7b6b97e0760cc45db
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.2\mfc90u.dll
executable
MD5: b9030d821e099c79de1c9125b790e2da
SHA256: e30aabb518361fbeaf8068ffc786845ee84abbf1f71ae7d2733a11286531595a
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1033.dll
executable
MD5: 9edeb8b1c5c0a4cd3a3016b85108127d
SHA256: 9bf7026a47daab7bb2948fd23e8cf42c06dd2e19ef8cdea0af7367453674a8f9
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.2\mfcm90.dll
executable
MD5: d4e7c1546cf3131b7d84b39f8da9e321
SHA256: c4243ba85c2d130b4dec972cd291916e973d9d60fac5ceea63a01837ecc481c2
3888
msiexec.exe
C:\install.res.2052.dll
executable
MD5: d7366b34e8afb605c39ef56e2201fe85
SHA256: f7aa6ebf1413a6e4816bcad5b77c47b6bbe0cfc05cafde4aa872abe3fbd5e62b
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1040.dll
executable
MD5: 6310ab8fc9e3dbee80592fc453a34fee
SHA256: 7774f2436c96a70b0cdc8176883ee7a4614353f17ad61bfbd5a8d7a1906483d3
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90cht.dll
executable
MD5: f3c53b5b47ab2d76fe2bbd7b3410fd63
SHA256: 416641841917752d9ea6d90ff3d59e1fbf59b5bcfa9f9ffcf2900bfa3c76603d
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.1\msvcm90.dll
executable
MD5: 4a8bc195abdc93f0db5dab7f5093c52f
SHA256: b371af3ce6cb5d0b411919a188d5274df74d5ee49f6dd7b1ccb5a31466121a18
3888
msiexec.exe
C:\install.res.1033.dll
executable
MD5: 9edeb8b1c5c0a4cd3a3016b85108127d
SHA256: 9bf7026a47daab7bb2948fd23e8cf42c06dd2e19ef8cdea0af7367453674a8f9
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1041.dll
executable
MD5: 13ed4517152203de4bc52acc0255d952
SHA256: 6183324fe24006bc3d8928029dcaccbdae517eb09727f5dd47ea5aaeed3ee26d
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90jpn.dll
executable
MD5: 90c9666e1f1bb578c35c26cfce10e2d8
SHA256: 6b6259b876972eb7507d052d4eac068555bea6973643db7050c6606d46beeca7
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.2\mfcm90u.dll
executable
MD5: 371226b8346f29011137c7aa9e93f2f6
SHA256: 5b08fe55e4bbf2fbfd405e2477e023137cfceb4d115650a5668269c03300a8f8
3888
msiexec.exe
C:\install.res.1028.dll
executable
MD5: 4151a4d07640863783f837e588235837
SHA256: 58475a90250c6818f73763775eea6379e06da6c38e8d2cf0f54eb6112a0a6aee
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1028.dll
executable
MD5: 4151a4d07640863783f837e588235837
SHA256: 58475a90250c6818f73763775eea6379e06da6c38e8d2cf0f54eb6112a0a6aee
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90deu.dll
executable
MD5: 03f005368955cd4b005b1bf8ca592f7a
SHA256: 0a05be79a6d3fb023001426b56a9d7a76d7ddea900fb4d6a762e42e4bf510925
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.1\msvcp90.dll
executable
MD5: 6de5c66e434a9c1729575763d891c6c2
SHA256: 4f7ed27b532888ce72b96e52952073eab2354160d1156924489054b7fa9b0b1a
3888
msiexec.exe
C:\install.res.1036.dll
executable
MD5: 5b6ff470cfa7087690e61f87e81ef78a
SHA256: 2d1c0a1b17266cff3be7d46cf3020b176e4a058fd7fc57f7b6b97e0760cc45db
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1042.dll
executable
MD5: 0d4fb4095ea49c1ec89b9e8db0b936a3
SHA256: 7d86f3ba0232c2ac4b4fce96e4cebb23700312a032d5d0db988ec6b358be1686
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90ita.dll
executable
MD5: 940258d5363f7197a989d64d85d29bf4
SHA256: 220f3f640cf165988561fea9e2fb828c2d9ca8ed2d943f14b3a6e055f11a4f58
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.1\msvcr90.dll
executable
MD5: e7d91d008fe76423962b91c43c88e4eb
SHA256: ed0170d3de86da33e02bfa1605eec8ff6010583481b1c530843867c1939d2185
3888
msiexec.exe
C:\install.res.3082.dll
executable
MD5: 41bb37a347121f3e5e88d85100638b79
SHA256: 320c305177ab4ec6e00883a2cf0886019b5d36557219e4a188cf9df3768f157f
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.2052.dll
executable
MD5: d7366b34e8afb605c39ef56e2201fe85
SHA256: f7aa6ebf1413a6e4816bcad5b77c47b6bbe0cfc05cafde4aa872abe3fbd5e62b
3888
msiexec.exe
C:\install.res.1040.dll
executable
MD5: 6310ab8fc9e3dbee80592fc453a34fee
SHA256: 7774f2436c96a70b0cdc8176883ee7a4614353f17ad61bfbd5a8d7a1906483d3
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.1\vcomp90.dll
executable
MD5: f6a85f3b0e30c96c993c69da6da6079e
SHA256: ffc774f6f055b1a9a899ab76dac3e141f582ce19dae0b3d4dff9d93916b42d09
3888
msiexec.exe
C:\install.res.1041.dll
executable
MD5: 13ed4517152203de4bc52acc0255d952
SHA256: 6183324fe24006bc3d8928029dcaccbdae517eb09727f5dd47ea5aaeed3ee26d
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.3082.dll
executable
MD5: 41bb37a347121f3e5e88d85100638b79
SHA256: 320c305177ab4ec6e00883a2cf0886019b5d36557219e4a188cf9df3768f157f
3888
msiexec.exe
C:\install.res.1042.dll
executable
MD5: 0d4fb4095ea49c1ec89b9e8db0b936a3
SHA256: 7d86f3ba0232c2ac4b4fce96e4cebb23700312a032d5d0db988ec6b358be1686
3888
msiexec.exe
C:\Windows\Installer\$PatchCache$\Managed\6F9E66FF7E38E3A3FA41D89E8A906A4A\9.0.21022\FL_msdia71_dll_2_60035_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
executable
MD5: bbb996eb044fd1657415e3b0ad70b722
SHA256: 54c0726edc212729fb004da9e2e87289f072f7872ead7072f008a4f7b4ae801b
3888
msiexec.exe
C:\install.exe
executable
MD5: 520a6d1cbcc9cf642c625fe814c93c58
SHA256: 08966ce743aa1cbed0874933e104ef7b913188ecd8f0c679f7d8378516c51da2
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.res.1031.dll
executable
MD5: 3b8a82e04238655eaef97e074fb29911
SHA256: 5e49c21b9a15c3a0fddde7ddc32fda220302ee57b8aff66f4f78b370e049410d
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90enu.dll
executable
MD5: 3be57351529e0f2ba7742cdf2b05316b
SHA256: a3e2c202e556791dee9d18962ca6780761b415313bcd104c2e621ba4089801a4
3888
msiexec.exe
C:\Windows\Installer\37c992.msi
executable
MD5: e0951d3cb1038eb2d2b2b2f336e1ab32
SHA256: 507ac60e145057764f13cf1ad5366a7e15ddc0da5cc22216f69e3482697d5e88
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.0\atl90.dll
executable
MD5: 64eca1f64e4a988a6c5c93f3e5d66236
SHA256: ab93df816c284ac247b9087663bc449beb26e6f64d9f8a6be2efecafa7a9cedc
3888
msiexec.exe
C:\VC_RED.MSI
executable
MD5: e0951d3cb1038eb2d2b2b2f336e1ab32
SHA256: 507ac60e145057764f13cf1ad5366a7e15ddc0da5cc22216f69e3482697d5e88
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.2\mfc90.dll
executable
MD5: 462ddcc5eb88f34aed991416f8e354b2
SHA256: 287bd98054c5d2c4126298ee50a2633edc745bc76a1ce04e980f3ecc577ce943
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\mfc90chs.dll
executable
MD5: fc1f85e5d3f477e8a9351b5a0a9bcdcc
SHA256: 5936dd619e57eb295172ad930890478d67fabefe6eb26997c5706127c5395c15
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.exe
executable
MD5: 520a6d1cbcc9cf642c625fe814c93c58
SHA256: 08966ce743aa1cbed0874933e104ef7b913188ecd8f0c679f7d8378516c51da2
3888
msiexec.exe
C:\vcredist.bmp
image
MD5: 06fba95313f26e300917c6cea4480890
SHA256: 594884a8006e24ad5b1578cd7c75aca21171bb079ebdc4f6518905bcf2237ba1
3888
msiexec.exe
C:\VC_RED.cab
compressed
MD5: e10f2f6e6379e9185f71aec1421f37b4
SHA256: 9681bcfd73c610eb6a9538d872c1e7844548fca341f22fb66ccadb4d78530b4d
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.1\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375.cat
cat
MD5: af01d7ce6d8e6ccc1eaad3b5d356bf5c
SHA256: 534cf013667c78b2ecf44e00183c95e4c2336f1e150a38452cd7e61ec2a73bfc
3888
msiexec.exe
C:\Windows\Installer\37c990.ipi
––
MD5:  ––
SHA256:  ––
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.4\9.0.21022.8.policy
xml
MD5: ed9f25c8eb92d53eaa4db58623584dfd
SHA256: c787b620de76b1443342f498421521bae93ff67471544cae5f8d7f5eb4bb0e93
3888
msiexec.exe
C:\install.ini
text
MD5: 0da9ab4977f3e7ba8c65734df42fdab6
SHA256: 672621b056188f8d3fa5ab8cd3df4f95530c962af9bb11cf7c9bd1127b3c3605
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\vc_red.cab
compressed
MD5: e10f2f6e6379e9185f71aec1421f37b4
SHA256: 9681bcfd73c610eb6a9538d872c1e7844548fca341f22fb66ccadb4d78530b4d
3888
msiexec.exe
C:\globdata.ini
text
MD5: 0a6b586fabd072bd7382b5e24194eac7
SHA256: 7912e3fcf2698cf4f8625e563cd8215c6668739cae18bd6f27af2d25bec5c951
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.3\9.0.21022.8.policy
xml
MD5: 2fa96a50f3ce62f5ae14783239ba4d80
SHA256: 0da633647bcebabcb569917cb392b89d51ec4fa17abe11f5ae46a0b75a347491
3888
msiexec.exe
C:\eula.1042.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\eula.1041.txt
text
MD5: 9b15a3a055cc6e67ea191a1b7885649a
SHA256: cac11bde0f7967389f9795dc2f2a5aa22b2c51d1a6ab0b0064df72dc3eb192ae
3888
msiexec.exe
C:\eula.1040.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\eula.1033.txt
text
MD5: 99c22d4a31f4ead4351b71d6f4e5f6a1
SHA256: 93a3c629fecfd10c1cf614714efd69b10e89cfcaf94c2609d688b27754e4ab41
3888
msiexec.exe
C:\eula.1031.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\eula.3082.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\eula.1036.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.2\9.0.21022.8.policy
xml
MD5: 803c5349ac33d311dfac5fe62dda79eb
SHA256: b2905920263f5b0017f84239ef098c8ce181779e80a0b90b320ac02ddd9e6e62
3888
msiexec.exe
C:\eula.1028.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\Config.Msi\37c991.rbs
––
MD5:  ––
SHA256:  ––
3888
msiexec.exe
C:\eula.2052.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\Users\admin\AppData\Local\Temp\dd_vcredistMSI0C57.txt
text
MD5: bbd68f00f3eeddbb78a658761638db46
SHA256: d8502f5dd1e1317c59aa99b6660ec1d0bca5e1ff7bddd76fe15b448524aa2948
4092
install.exe
C:\Users\admin\AppData\Local\Temp\VWLD769.tmp
––
MD5:  ––
SHA256:  ––
3888
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF0B64EFCEFF6B7334.TMP
––
MD5:  ––
SHA256:  ––
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.5\9.0.21022.8.policy
xml
MD5: 6fd0fb5713222363091fd31e38e3c0df
SHA256: db285d0baf283a67a093358d2ac0feb011b40f18a41cea2f93bd18c470586583
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.6\9.0.21022.8.policy
xml
MD5: 6a862b008e87d447cd900dc6a793b2d3
SHA256: c1da105c2da39ce425867dabf5d06ff62df2535ae82be4e9c37299991a8c8f02
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a.manifest
xml
MD5: 6439b46d6d9cb337ddf2d8e643455951
SHA256: 81e13dc44e21fca2b095e82c34294c199d37428f32de36d5ffa6cd3b54f88d7b
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.1\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1.manifest
xml
MD5: 1b2b5a8fa0ab8c76ec505f786a74cdb2
SHA256: b189460384701bcc280c0ac3c9e007e705106d6b8ac8ee52e118036f496b3c1d
3888
msiexec.exe
C:\Windows\Installer\MSICAB7.tmp
binary
MD5: 19990b9901ff4a9403dfafd9c6a913bf
SHA256: ed23c21081eae120ec33a05fcca4c8b65d3cbe54725667afd9cd1ef152e0a839
3888
msiexec.exe
C:\Windows\Installer\37c990.ipi
binary
MD5: da4ca4fee8671e93c62ca2a20c7462e1
SHA256: f61b82209c4c6776da2bec328e9ea550df91e26c8bf7f0b55b75dc8a62b7201d
3888
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF7CE0E67C4BB75FE3.TMP
––
MD5:  ––
SHA256:  ––
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.2\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a.manifest
xml
MD5: 17683bda76942b55361049b226324be9
SHA256: 27c573d1de24a2cef2b2cac0850bf079a02d478d54cf00617a1d2f08a17109f5
4092
install.exe
C:\Users\admin\AppData\Local\Temp\dd_vcredistMSI0C57.txt
text
MD5: e6192dfa480c0777c4bab770f30d1c5f
SHA256: 07a0bcebb766993b93f138552fa6cf9705fafb26e778c652e70406d5c7c54610
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1040.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.3082.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1036.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1041.txt
text
MD5: 9b15a3a055cc6e67ea191a1b7885649a
SHA256: cac11bde0f7967389f9795dc2f2a5aa22b2c51d1a6ab0b0064df72dc3eb192ae
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\vcredist.bmp
image
MD5: 06fba95313f26e300917c6cea4480890
SHA256: 594884a8006e24ad5b1578cd7c75aca21171bb079ebdc4f6518905bcf2237ba1
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\install.ini
text
MD5: 0da9ab4977f3e7ba8c65734df42fdab6
SHA256: 672621b056188f8d3fa5ab8cd3df4f95530c962af9bb11cf7c9bd1127b3c3605
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.2052.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1031.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\globdata.ini
text
MD5: 0a6b586fabd072bd7382b5e24194eac7
SHA256: 7912e3fcf2698cf4f8625e563cd8215c6668739cae18bd6f27af2d25bec5c951
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1028.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.0\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9.manifest
xml
MD5: 69e6e75b8251a7749435e331e29912a4
SHA256: 9a900c1d0801730b675a8c67048f80fde41af58d52c72d8545d4a405cd10f4d6
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.1\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375.manifest
xml
MD5: 4f9ed5efa4f7b75bcfe0f36c36ee5cb6
SHA256: ff718390133b400ee679177b2902bbb918db148bbb4ababa03d0a1df325b3303
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.5\9.0.21022.8.cat
cat
MD5: dc85d95fbf7f92b8a33bba6c9c3187ff
SHA256: 5ba439378027b451247f04ae2a57f0cfe7c12eb038148c7ce49ae9af2ee3822b
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.2\9.0.21022.8.cat
cat
MD5: 2a53210e743b480d2e81767e51834443
SHA256: ab5212c08b080c18511d0f344aedd3cbb0cfda87bc12ac2bb88e9f8ef7635b5e
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.1\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1.cat
cat
MD5: f0dff36c6ac830978fe6525e37b22149
SHA256: a768d09fe494b7325cb036213b4704e844529604bd7621580cc69b6c76e3baa8
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.2\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a.cat
cat
MD5: f787891d393985a92dc71301df7bab02
SHA256: 74ff96d7d46907976c63c8c8e3a7457e950c6fd8a7661600aab23382051de0e0
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.3\9.0.21022.8.cat
cat
MD5: 0a44ebfafaca37df14bb82d16ae41338
SHA256: 1154a0dd8ec7062351d700a2d07b3bb5154c840bfc84077d20f6947d1e08bb6f
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.4\9.0.21022.8.cat
cat
MD5: f3844f7a32ca3e2f349d999ebed77501
SHA256: ae866863bd234bc6fd016eab6d40c7fc996cb58ab511179d087596835c8182ab
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.6\9.0.21022.8.cat
cat
MD5: 20da0c183c2241fd157046e698fd487d
SHA256: be665d05f40feae483878d15c39e6fff25800f58d7364b309a49983afcd19841
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727334.0\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a.cat
cat
MD5: 9a435850ccb04dff36009ea253ac5c99
SHA256: 17187dd8585ec10ff914a12b3996436e3822c0d7ab634fd243562bf6b0a10711
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1033.txt
text
MD5: 99c22d4a31f4ead4351b71d6f4e5f6a1
SHA256: 93a3c629fecfd10c1cf614714efd69b10e89cfcaf94c2609d688b27754e4ab41
2852
VC2008.EXE
C:\068db81b0192cc457d10422414c14f\eula.1042.txt
text
MD5: 9147a93f43d8e58218ebcb15fda888c9
SHA256: a75019ac38e0d3570633fa282f3d95d20763657f4a2fe851fae52a3185d1eded
3888
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170727318.0\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9.cat
cat
MD5: 34ca60a44c62d5f8eb6dfccb1f3cb214
SHA256: 611281d2ae7e5728e1298dcbf5aa626dad5a5a746964c9c425d183f86d0289de
4092
install.exe
C:\Users\admin\AppData\Local\Temp\dd_vcredistMSI0C57.txt
text
MD5: bbd68f00f3eeddbb78a658761638db46
SHA256: d8502f5dd1e1317c59aa99b6660ec1d0bca5e1ff7bddd76fe15b448524aa2948

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.