General Info

File name

sfx.exe

Full analysis
https://app.any.run/tasks/6d35ad9c-5c94-4504-87c1-b364cd0617f8
Verdict
Malicious activity
Analysis date
12/6/2018, 14:19:02
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

2ceada9ff365c2270d4f5009559f6317

SHA1

fa20d954bdbce36fc4c2a43e4d7398c5ffcf7953

SHA256

cc4af00148c278ba5d22fbf13abbdf0ce6832b6941b617f6794eee6bced60c61

SSDEEP

49152:nJqi6DGIafdSjrBNGgMFOdJe+LvahKKBo0/0u1YwRdDEOwKGdfdZStr0+253f0ey:JD5IrR/2ONoKKBN/pyYwXKt4+25vxRlw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • AdhocSettingService.exe (PID: 3736)
  • QuickProjection.exe (PID: 2308)
  • setup.exe (PID: 3824)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 3212)
  • setup.exe (PID: 3824)
  • sfx.exe (PID: 3760)
Starts Microsoft Installer
  • setup.exe (PID: 3824)
Reads internet explorer settings
  • sfx.exe (PID: 3760)
Creates files in the user directory
  • QuickProjection.exe (PID: 2308)
Creates a software uninstall entry
  • msiexec.exe (PID: 3212)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 2140)
Searches for installed software
  • msiexec.exe (PID: 3212)
Creates files in the program directory
  • msiexec.exe (PID: 3212)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (64.6%)
.dll
|   Win32 Dynamic Link Library (generic) (15.4%)
.exe
|   Win32 Executable (generic) (10.5%)
.exe
|   Generic Win/DOS Executable (4.6%)
.exe
|   DOS Executable Generic (4.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:08:14 21:15:49+02:00
PEType:
PE32
LinkerVersion:
14
CodeSize:
188416
InitializedDataSize:
196096
UninitializedDataSize:
null
EntryPoint:
0x1cab5
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
14-Aug-2016 19:15:49
Detected languages
English - United States
Debug artifacts
D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000108
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
14-Aug-2016 19:15:49
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0002DFE8 0x0002E000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.71025
.rdata 0x0002F000 0x000099D0 0x00009A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.15287
.data 0x00039000 0x0001F8B8 0x00000C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.29547
.gfids 0x00059000 0x000000F0 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 2.12367
.rsrc 0x0005A000 0x00004680 0x00004800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.63811
.reloc 0x0005F000 0x00001F8C 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.62986
Resources
1

2

3

4

7

8

9

10

11

12

13

14

15

16

100

101

ASKNEXTVOL

GETPASSWORD1

LICENSEDLG

RENAMEDLG

REPLACEFILEDLG

STARTDLG

Imports
    KERNEL32.dll

    COMCTL32.dll (delay-loaded)

Exports

    No exports.

Screenshots

Processes

Total processes
42
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

+
drop and start start sfx.exe setup.exe msiexec.exe no specs msiexec.exe vssvc.exe no specs drvinst.exe no specs adhocsettingservice.exe no specs quickprojection.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3760
CMD
"C:\Users\admin\Desktop\sfx.exe"
Path
C:\Users\admin\Desktop\sfx.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\sfx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\riched20.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\users\admin\desktop\204635\setup.exe
c:\windows\system32\sfc.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll

PID
3824
CMD
"C:\Users\admin\Desktop\204635\setup.exe" -i
Path
C:\Users\admin\Desktop\204635\setup.exe
Indicators
Parent process
sfx.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Ricoh
Description
Setup Launcher Unicode
Version
1.3.0.28
Modules
Image
c:\users\admin\desktop\204635\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msi.dll
c:\windows\system32\msiexec.exe

PID
4012
CMD
MSIEXEC.EXE /i "C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\RICOH QuickProjection.msi" TRANSFORMS="C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\1033.MST" SETUPEXEDIR="C:\Users\admin\Desktop\204635" SETUPEXENAME="setup.exe"
Path
C:\Windows\system32\MSIEXEC.EXE
Indicators
No indicators
Parent process
setup.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\propsys.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\msihnd.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\msls31.dll

PID
3212
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2140
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
3096
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000550" "00000330"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
3736
CMD
"C:\Program Files\Ricoh\QuickProjection\AdhocSettingService.exe"
Path
C:\Program Files\Ricoh\QuickProjection\AdhocSettingService.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Description
Version
Modules
Image
c:\program files\ricoh\quickprojection\adhocsettingservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2308
CMD
"C:\Program Files\Ricoh\QuickProjection\QuickProjection.exe"
Path
C:\Program Files\Ricoh\QuickProjection\QuickProjection.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
RICOH
Description
QuickProjection
Version
1.3.0.28
Modules
Image
c:\program files\ricoh\quickprojection\quickprojection.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\version.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oledlg.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll

Registry activity

Total events
726
Read events
473
Write events
246
Delete events
7

Modification events

PID
Process
Operation
Key
Name
Value
3760
sfx.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3760
sfx.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000FAE68669668DD4018C0C0000340F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
4000000000000000FAE68669668DD4018C0C0000340F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
20
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
4000000000000000F6A5076A668DD4018C0C0000340F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
400000000000000050080A6A668DD4018C0C0000E80D0000E8030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
40000000000000007873F86A668DD4018C0C0000E80D0000E8030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
4000000000000000DEA69F70668DD4018C0C0000340F0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
4000000000000000DEA69F70668DD4018C0C0000340F0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
40000000000000005457B070668DD4018C0C0000340F0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
4000000000000000246AC370668DD4018C0C000014080000E9030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
4000000000000000A841DB70668DD4018C0C000014080000E9030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
4000000000000000A841DB70668DD4018C0C0000D00A0000F9030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
40000000000000006A2DE770668DD4018C0C0000D00A0000F9030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
40000000000000001EF2EB70668DD4018C0C0000340F00000A040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
40000000000000007EF9F671668DD4018C0C0000E80B00000A040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
40000000000000007EF9F671668DD4018C0C0000340F0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
40000000000000007EF9F671668DD4018C0C0000340F0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
20
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
FAE68669668DD401
3212
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
8C0C00000A912165668DD401
3212
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
F861612FA4481D6B4A508CCCC3EDEA038189BC67121F7B9D0DF7F341F4928CC7
3212
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\256511.ipi
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\256512.rbs
30707046
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\256512.rbsLow
1924352384
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86909C9F9555E7246964F51FFDF7772D
76396891177255849A58A7A8FFF3A29F
C:\Program Files\Ricoh\QuickProjection\AdhocSettingService.exe
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD42BC512928211408319BC108128A6C
76396891177255849A58A7A8FFF3A29F
C:\Program Files\Ricoh\QuickProjection\QuickProjection.exe
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\771E8C0537764034A831D8F23B291E25
76396891177255849A58A7A8FFF3A29F
C:\Program Files\Ricoh\QuickProjection\DeleteSettingFiles.exe
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Ricoh\QuickProjection\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Ricoh\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ricoh\QuickProjection\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ricoh\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
RegOwner
admin
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
RegCompany
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
ProductID
none
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
LocalPackage
C:\Windows\Installer\256513.msi
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
AuthorizedCDFPrefix
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Comments
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Contact
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
DisplayVersion
1.3.0.28
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
HelpLink
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
HelpTelephone
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
InstallDate
20181206
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
InstallLocation
C:\Program Files\Ricoh\QuickProjection\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
InstallSource
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
ModifyPath
MsiExec.exe /I{19869367-2771-4855-A985-7A8AFF3F2AF9}
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Publisher
Ricoh
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Readme
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Size
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
EstimatedSize
7672
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
UninstallString
MsiExec.exe /I{19869367-2771-4855-A985-7A8AFF3F2AF9}
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
URLInfoAbout
http://www.Ricoh.com
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
URLUpdateInfo
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
VersionMajor
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
VersionMinor
3
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
WindowsInstaller
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Version
16973824
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
Language
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
AuthorizedCDFPrefix
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Comments
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Contact
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
DisplayVersion
1.3.0.28
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
HelpLink
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
HelpTelephone
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
InstallDate
20181206
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
InstallLocation
C:\Program Files\Ricoh\QuickProjection\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
InstallSource
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
ModifyPath
MsiExec.exe /I{19869367-2771-4855-A985-7A8AFF3F2AF9}
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Publisher
Ricoh
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Readme
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Size
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
EstimatedSize
7672
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
UninstallString
MsiExec.exe /I{19869367-2771-4855-A985-7A8AFF3F2AF9}
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
URLInfoAbout
http://www.Ricoh.com
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
URLUpdateInfo
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
VersionMajor
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
VersionMinor
3
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
WindowsInstaller
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Version
16973824
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
Language
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\08D8DF0D7A09CD2418716B4FF4034742
76396891177255849A58A7A8FFF3A29F
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\InstallProperties
DisplayName
RICOH QuickProjection
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19869367-2771-4855-A985-7A8AFF3F2AF9}
DisplayName
RICOH QuickProjection
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\76396891177255849A58A7A8FFF3A29F
QPApp_Files
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\Features
QPApp_Files
^yq?yBxTG9Vj$Yv~5f_lctG!*7ldv88hb7,5(*qhE]yzAJ'pU9(`&@3Mm6_B
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\76396891177255849A58A7A8FFF3A29F\Patches
AllPatches
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
ProductName
RICOH QuickProjection
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
PackageCode
8F1A5BCC627110D4DAF23D810653EB3D
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
Language
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
Version
16973824
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
Transforms
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\1033.MST
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
Assignment
1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
AdvertiseFlags
388
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
ProductIcon
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\ARPPRODUCTICON.exe
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
InstanceType
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
AuthorizedLUAApp
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
DeploymentFlags
2
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\08D8DF0D7A09CD2418716B4FF4034742
76396891177255849A58A7A8FFF3A29F
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F\SourceList
PackageName
RICOH QuickProjection.msi
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F\SourceList\Net
1
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F\SourceList\Media
DiskPrompt
[1]
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F\SourceList\Media
1
DISK1;1
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F
Clients
:
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\76396891177255849A58A7A8FFF3A29F\SourceList
LastUsedSource
n;1;C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages
C:\Windows\Installer\256510.mst
0
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
96
3212
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
3212
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F
3212
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3212
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3212
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
3212
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3212
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3212
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
400000000000000088A4266A668DD4015C0800005C0E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
400000000000000088A4266A668DD4015C080000440A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
400000000000000088A4266A668DD4015C080000740E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000088A4266A668DD4015C080000400A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
400000000000000096CB2D6A668DD4015C0800005C0E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000F02D306A668DD4015C080000400A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
40000000000000004A90326A668DD4015C080000740E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000FE54376A668DD4015C080000440A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
4000000000000000246AC370668DD4015C080000440A000001040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
4000000000000000246AC370668DD4015C080000440A000001040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000D82EC870668DD4015C080000400A0000E9030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000D82EC870668DD4015C080000740E0000E9030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000D82EC870668DD4015C080000440A0000E9030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
40000000000000008CF3CC70668DD4015C080000400A0000E9030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
40000000000000008CF3CC70668DD4015C080000400A000001000000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
40000000000000008CF3CC70668DD4015C080000440A0000E9030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
40000000000000008CF3CC70668DD4015C080000440A000001000000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
4000000000000000E655CF70668DD4015C080000740E0000E9030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000E655CF70668DD4015C080000740E000001000000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
400000000000000010CBE470668DD4015C080000740E0000F9030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
400000000000000010CBE470668DD4015C080000440A0000F9030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
400000000000000010CBE470668DD4015C080000400A0000F9030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
400000000000000010CBE470668DD4015C080000440A0000F9030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
400000000000000010CBE470668DD4015C080000740E0000F9030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
400000000000000010CBE470668DD4015C080000400A0000F9030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000001EF2EB70668DD4015C080000D80B000002040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000B2276371668DD4015C080000D80B000002040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
40000000000000000C8A6571668DD4015C080000D80B0000EA030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
400000000000000074136F71668DD4015C080000100B0000EA030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
400000000000000074136F71668DD4015C080000240B0000EA030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
400000000000000074136F71668DD4015C080000180B0000EA030000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
40000000000000006E9B9771668DD4015C080000240B0000EA030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
40000000000000006E9B9771668DD4015C080000240B000002000000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
4000000000000000C8FD9971668DD4015C080000180B0000EA030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000C8FD9971668DD4015C080000180B000002000000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
4000000000000000C8FD9971668DD4015C080000100B0000EA030000000000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000C8FD9971668DD4015C080000100B000002000000010000000100000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
4000000000000000D0ACC971668DD4015C080000D80B0000EA030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
4000000000000000D0ACC971668DD4015C080000D80B0000EB030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
4000000000000000D0ACC971668DD4015C080000D80B0000EC030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
40000000000000002A0FCC71668DD4015C080000240B0000EB030000010000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
40000000000000002A0FCC71668DD4015C080000240B0000EB030000000000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000002A0FCC71668DD4015C080000240B000003000000010000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000002A0FCC71668DD4015C080000480C0000FC030000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
40000000000000002A0FCC71668DD4015C080000D80B0000EC030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
40000000000000002A0FCC71668DD4015C080000D80B0000ED030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
4000000000000000DED3D071668DD4015C080000D80B0000ED030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
4000000000000000DED3D071668DD4015C080000D80B0000EE030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
40000000000000009298D571668DD4015C080000080B0000EB030000010000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
40000000000000009298D571668DD4015C080000080B0000EB030000000000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000009298D571668DD4015C080000080B000003000000010000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000009298D571668DD4015C080000600C0000FC030000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
4000000000000000ECFAD771668DD4015C080000D80B0000EE030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
4000000000000000ECFAD771668DD4015C080000D80B0000F0030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
4000000000000000ECFAD771668DD4015C080000D80B0000F0030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
4000000000000000ECFAD771668DD4015C080000D80B0000EF030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
4000000000000000A0BFDC71668DD4015C080000100B0000EB030000010000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
40000000000000005484E171668DD4015C080000100B0000EB030000000000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000005484E171668DD4015C080000100B000003000000010000000200000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000005484E171668DD4015C080000C80D0000FC030000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
40000000000000005484E171668DD4015C080000D80B0000EF030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
40000000000000005484E171668DD4015C080000D80B0000EB030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
40000000000000005484E171668DD4015C080000D80B000003040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
40000000000000005484E171668DD4015C080000D80B000003040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
40000000000000005484E171668DD4015C080000D80B0000FD030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
40000000000000005484E171668DD4015C080000A80D0000FD030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
400000000000000070D2EF71668DD4015C080000A80D0000FD030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
400000000000000070D2EF71668DD4015C080000D80B0000FD030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000070D2EF71668DD4015C080000A80D0000FE030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
40000000000000007EF9F671668DD4015C080000A80D0000FE030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
40000000000000007EF9F671668DD4015C080000A80D0000FF030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
40000000000000007EF9F671668DD4015C080000A80D0000FF030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000070D2EF71668DD4015C080000D80B0000FE030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
40000000000000007EF9F671668DD4015C080000D80B0000FE030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
40000000000000007EF9F671668DD4015C080000D80B0000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
40000000000000007EF9F671668DD4015C080000D80B0000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
40000000000000007EF9F671668DD4015C080000E00D000004040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
40000000000000007EF9F671668DD4015C080000E00D000004040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
40000000000000007EF9F671668DD4015C080000D80B000005040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
40000000000000007EF9F671668DD4015C080000D80B000005040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
40000000000000007EF9F671668DD4015C080000D80B0000F4030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
40000000000000007EF9F671668DD4015C080000D80B0000F4030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
40000000000000007EF9F671668DD4015C080000D80B0000F2030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
40000000000000008C20FE71668DD4015C080000240B0000F2030000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
40000000000000008C20FE71668DD4015C080000080B0000F2030000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000008C20FE71668DD4015C080000600C0000FC030000000000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000008C20FE71668DD4015C080000480C0000FC030000000000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
40000000000000008C20FE71668DD4015C080000240B0000F2030000000000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000008C20FE71668DD4015C080000240B000004000000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
40000000000000008C20FE71668DD4015C080000080B0000F2030000000000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
40000000000000008C20FE71668DD4015C080000040B0000F2030000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000008C20FE71668DD4015C080000080B000004000000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000008C20FE71668DD4015C080000C80D0000FC030000000000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
40000000000000008C20FE71668DD4015C080000040B0000F2030000000000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000008C20FE71668DD4015C080000040B000004000000010000000300000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
40000000000000008C20FE71668DD4015C080000D80B0000F2030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
40000000000000008C20FE71668DD4015C080000D80B000006040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
40000000000000000A803E72668DD4015C080000D80B000006040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
40000000000000000A803E72668DD4015C080000D80B0000F5030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
4000000000000000CC6B4A72668DD4015C080000180B0000F5030000010000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
4000000000000000CC6B4A72668DD4015C080000240B0000F5030000010000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
4000000000000000CC6B4A72668DD4015C080000100B0000F5030000010000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
4000000000000000CC6B4A72668DD4015C080000100B0000F5030000000000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000CC6B4A72668DD4015C080000100B000005000000010000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
4000000000000000CC6B4A72668DD4015C080000240B0000F5030000000000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000CC6B4A72668DD4015C080000240B000005000000010000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
4000000000000000228DCD72668DD4015C080000180B0000F5030000000000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000228DCD72668DD4015C080000180B000005000000010000000400000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
4000000000000000228DCD72668DD4015C080000D80B0000F5030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
4000000000000000228DCD72668DD4015C080000D80B000007040000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
40000000000000000EEEEE72668DD4015C080000D80B000007040000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
4000000000000000468A0B73668DD4015C080000D80B0000FB030000010000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
4000000000000000A0EC0D73668DD4015C080000040B0000FB030000010000000500000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
4000000000000000A0EC0D73668DD4015C080000080B0000FB030000010000000500000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
4000000000000000A0EC0D73668DD4015C080000040B0000FB030000000000000500000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
4000000000000000A0EC0D73668DD4015C080000080B0000FB030000000000000500000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
4000000000000000A0EC0D73668DD4015C080000240B0000FB030000010000000500000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
4000000000000000A0EC0D73668DD4015C080000240B0000FB030000000000000500000000000000403345210F1C374387E6E33A5F735D200000000000000000
2140
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
4000000000000000A0EC0D73668DD4015C080000D80B0000FB030000000000000000000000000000403345210F1C374387E6E33A5F735D200000000000000000
3096
DrvInst.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US

Files activity

Executable files
10
Suspicious files
12
Text files
414
Unknown types
2

Dropped files

PID
Process
Filename
Type
3760
sfx.exe
C:\Users\admin\Desktop\204635\setup.exe
executable
MD5: cc6d129bddee38b1c1333ae924f7f215
SHA256: 805c8032c1047fe500e8918e2b4a1b0353c91ddfa80168bfad74679233126dba
3212
msiexec.exe
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\QuickProjection.ex_F9E1CC139A4842EAB3ED3AEB78FC555C.exe
executable
MD5: 50a0957010f0613b4cbb67523880bfa7
SHA256: ef24215fc64c0271c77b019416f6f725ede86ddea8d36e23d24a269c343b61c6
3212
msiexec.exe
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\QuickProjection.ex_7A5641CDFCA0401BA0BE45A902DC5294.exe
executable
MD5: 5a519f91f917ba91ea2acf2b344694c5
SHA256: bd8cd3d35f33c133e6569489e166d1caa85af7b77d53bcb5b4c668cf57a40d5d
3212
msiexec.exe
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\ARPPRODUCTICON.exe
executable
MD5: 0daf6444b7b1d8682e2393dd20858b32
SHA256: d3ef03af9cc4667ef3cce607920f0f716fe01c342c736af9d7c4a65c0b0d4cb2
3212
msiexec.exe
C:\Program Files\Ricoh\QuickProjection\DeleteSettingFiles.exe
executable
MD5: 8a23b16b2ef576ad64879e70665d856f
SHA256: 5070a81393ab9f6baab560bc81eb8de417c81c52c1ad2b1d05a74c6bbc4e53dd
3212
msiexec.exe
C:\Program Files\Ricoh\QuickProjection\QuickProjection.exe
executable
MD5: c78b21b92e302c7556c413a73c260566
SHA256: b3b13f77acaeed32175a355485d1976337d4ec22f07acedd29a777b6aaf83acc
3212
msiexec.exe
C:\Program Files\Ricoh\QuickProjection\AdhocSettingService.exe
executable
MD5: 383e86238bf1b5bfb8164975147c41ac
SHA256: 98d34fcea951a88e856a2017fcb01dfbc6d73ac5873c05646b7de1a1e74c90ff
3212
msiexec.exe
C:\Windows\Installer\25650f.msi
executable
MD5: 9339689a95aba6188c63b6dc9cfd19da
SHA256: b9a08e53bbb166c67700d2555d6c22555060fa7dcf299a615162005dd4da37b9
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\RICOH QuickProjection.msi
executable
MD5: 9339689a95aba6188c63b6dc9cfd19da
SHA256: b9a08e53bbb166c67700d2555d6c22555060fa7dcf299a615162005dd4da37b9
3212
msiexec.exe
C:\Windows\Installer\256513.msi
executable
MD5: 9339689a95aba6188c63b6dc9cfd19da
SHA256: b9a08e53bbb166c67700d2555d6c22555060fa7dcf299a615162005dd4da37b9
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cabFEF0.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\log\20181206132103268.cab
compressed
MD5: 9d2652fea1b7d8a9bf649c7ccd4bfd8a
SHA256: 60c4e3f27b416928df25ab7be9d673bacaad88da5f2a7624a12b24648c369e6f
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cabFEEF.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cabFEEE.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cabFEED.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\log\20181206132103268\app_20181206132103268.log
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\tr0300.html
html
MD5: 9a099a2af7edb6220212f301fb5b30f9
SHA256: f5a9827527faa588f03d17281d5d2ae407b72f038b480988eb974e3976d320c3
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\st0004.html
html
MD5: 3a1aca2123c50b79cc3d584846ca1cde
SHA256: 428438dc8c3356aa394f74ad8eb850f674a2afe61c45eec25c64c2785994eea7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\st0003.html
html
MD5: d68a95fdabe2ed823143b1460f6923ef
SHA256: b32405599307f505098b07c2dc1b161181afa1459e5bd39ae00d476f03668f0f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\st0005.html
html
MD5: fcd5c53d8bd83712015535c68583aff8
SHA256: 498ca6714221247b737c44e815c948c86f72ec3f29cb2e44aec00e4fc6686fb9
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\st0007.html
html
MD5: b23cd89dde6b3879b76e9f924d5dcc15
SHA256: c3adc5f05cdb8f8e7a59d285a0ceb9990cdda5a76f26303deb2dd6222573a192
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\tr0200.html
html
MD5: 9587d26cf060cd168c04b9d2e248826a
SHA256: 1af66df1ff9660e52ba9305959dba96a7b7e725529bee93f6b3a0126eaea9210
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\tr0100.html
html
MD5: fcd198080272a592427d1ecdbc93ec0c
SHA256: 2703bd7db3a833289a30e48523af1db7a7ef09c93a33d281727f182d82753f65
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\st0001.html
html
MD5: cb5f46d0bd310da14e8291bbc22b8c2c
SHA256: c8646a7dcd6d9f777bdc7b7d2fb9c18a85bbdc67f77039a7b378fd07baffc473
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\pj0003.html
html
MD5: f6591d17a55162d17affd698315a6316
SHA256: 5a340346b892dc651c26b752d50c13a9cf38b374cf4ad8b86aef329fc8ca2176
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\pj0000.html
html
MD5: d9a1c3c35076f37f8783e2ead337b679
SHA256: b7166e261557060e2d76ebf9834023f81a0edf9577f03a70eefc1e3c477ee6e1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\pj0002.html
html
MD5: f1dcba32873379cdb19d33aef382fca8
SHA256: e45e3d913bbc56725712017ad409a29499a87b3a1da6d518c2f38052d63766a5
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\pj0001.html
html
MD5: c5e075fa45949782fdae1c2bde1b7df6
SHA256: 51cadb77b87a382e6576e711a1114b1704124f40273dcad2fac59f700f805063
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\nwu_help.js
text
MD5: a81d4150ece0963def64f981fc02b1c3
SHA256: 50c90f792234478a208a2fc70f297073493d6024d4b852b04de008923c938107
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\index.html
html
MD5: eef2e144fc0bdbf80c9f72761c0a0c24
SHA256: 3a99b47920a268269664d0d9508990bb53ef8844a8af954ffe79a79ef7f8da84
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Setting Screen.gif
image
MD5: fdf74114ce7dbafb77e23b910ba5f207
SHA256: 6c013ed58cbd8c2c3022467a828321e71cd265a8bcdb794c6adcd3b52af175df
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Setting Screen Advanced.gif
image
MD5: 3b3577a194482ba809c163414212e0fd
SHA256: 82bc62f2a95359909b94c1ad8823bb3e1b2d687c57dffc63bc9820e8a252e9b1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Projection Screen (Play)_presentation.gif
image
MD5: 8d94ffb2db4330f7e0fdf548d5d5b05f
SHA256: ab49499ca3281e4966d04e5af405d8494dab02a48c4ca2f4c7e4b40e0c145236
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Projection Screen (Play).gif
image
MD5: 069b215f89a224d5f0070c2fd9ecb611
SHA256: 375c71a06baa4f951e4d2418fa8f5d26f33bd0154d1f0d6d12d0dde2ade0a2bf
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\control_panel.gif
image
MD5: ad257e6e77f7cc7df6d0fdc68ab24f62
SHA256: 86f11936a48b2c011001d1481a56cecfa36ef8c652e994c97af9299abdd4759f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Connect Screen_Inputed.gif
image
MD5: 06221712d1f1a60b789f079eea67f048
SHA256: 35f1db4a95c68a34ce0683908475292052423afb6c1393c88b6e8b9549fe1d8a
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Connect Screen Infra.gif
image
MD5: 795d4741eb1ee3e50de85c0d22db3961
SHA256: 1d3a935cf8961e8887b6e603adedd7dcb4f3f00eb1e2b96e2b08a33920d7fcfd
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Connect Screen.gif
image
MD5: e95c21c985945cfbb9501fec60299dfc
SHA256: f45611ebdd247db4da73a6189b7299de82772ff2b866351a3ce33a99652295b1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Connect Screen Infra_Selected.gif
image
MD5: 74c025cc07f86ab7aaccb82f72806b72
SHA256: 50cf4c8a5173ba1983d1310a7bd3e75fd9b6f904320dfba3f6309eeb69f14e14
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\zh\copyright.html
html
MD5: 97657f504042eb7e2d5a5232f8e5745b
SHA256: 8dcc02b457dd79a846ef133faa1c0ebf46ce6645a1417273110b079323fb636e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\tr0200.html
html
MD5: 5617f8039a1b12c725c66df6063aceeb
SHA256: 72d908dce121501eba01595e6bd784f78fc204ec48b3b932a3c3e36792e84c13
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\tr0300.html
html
MD5: de545e5a8b7b1e31f5ed0c9bb96619f4
SHA256: b337d4527cd4f1c7c95e900d235184d4be23887b238aaed9225593afb1c5de71
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\tr0100.html
html
MD5: cc2f5a3b79d1a19c79c130c8724f5aa0
SHA256: ad00f0465d36a292b34a52391be443a9f2a95cc3807cd04c5f3e4004f965a1e1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\st0007.html
html
MD5: ada725697af6b63c2c8b002e60b3646e
SHA256: f01376a45056905c4ba03b23869dae71c85ef49fd8f8c8887775eacd1242d298
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\st0003.html
html
MD5: 15434cf7e8b3ab8891e1845a62bda9b6
SHA256: a590d5985aee737da7548d97161df61698b7f7276e36b16083381eae3b56e9fa
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\st0005.html
html
MD5: 6be6f80e68e9150424025fd24a15b6b4
SHA256: b8c615c2c8b89fba6826c878a67b988ea9b381a8e1503d03e356a2d083590bf1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\st0004.html
html
MD5: 04076ae30311ed0ebef9a6f2fdb5795f
SHA256: 68ba683ed7924f292d43912f03a7e64bde9439d6f07f9e7e440dc7eeed3099e3
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\st0001.html
html
MD5: 6c985fc358f8d1a9468390347ac319ae
SHA256: a1bde8512d3ab82c9279534c48df45df4ddfc5c67ca30e29d5d6ffbe3702ee58
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\pj0002.html
html
MD5: 94f11bffd896823182361af40952021f
SHA256: 8f40ac6c360c1d9bca4ba09427aee44eb7c45680c891c04ccdd2c4ae51df4328
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\pj0001.html
html
MD5: 9ddb099232d2d34dc6858bf75777a7d8
SHA256: 9efef790852f788b10d8b6f471b93f00aa3144be78dbc6355ab9a793da0292ac
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\pj0003.html
html
MD5: 10f37a63f5ee24b80a746836b19465a7
SHA256: e31cd2be27ea46fa9d8d2a8356bf9728a39003c877295d533b669b9d48f86cd7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\index.html
html
MD5: 9169192fb29bfb6b96c53fbca959a0ce
SHA256: f25f6d548d613b551f79901f2ed5eb55403f924008054ee5d118b9669ca08cf8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\nwu_help.js
text
MD5: b732d2950c1be74a2b4ce094b06bef1c
SHA256: 2cab22df8b65ac894763ba1c0d6a3bfb9fd15ed82ac95b03b0f57fa93b7fdbee
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\pj0000.html
html
MD5: 2d0235c29ff8ec83e8b2c045efea83b2
SHA256: 20f23279143036a1c3f4b6e5be097ee064a37a02e0077691d050cb1c20efd068
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Setting Screen Advanced.gif
image
MD5: 63575de3d3571501e3c4a966585fa849
SHA256: 627e10d773ba68656ce786821fd1c01f5cc9e38e445f4db76eca5dae73c70693
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Setting Screen.gif
image
MD5: 35075af876e32df59ca9833329236de5
SHA256: a077543a0581b6275b7ff5331e11a29b9aeab8ed14505e28424fd719a4573f90
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Projection Screen (Play).gif
image
MD5: fd0f596ca790f3dac9ff798ab26666ce
SHA256: e9996dc5b431540fed8e370ea617046aab9d26027b32f986578624f380021b02
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Projection Screen (Play)_presentation.gif
image
MD5: 3a5af8e82cb19f5e66a3ee7dfed7b9a9
SHA256: 54e15e274be58747bbbcc805725313262fef2dbe87b5213de08db0fe1750e7ad
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\control_panel.gif
image
MD5: 103b86f8a82f79a74c9f153d6ebdff28
SHA256: 7e4dbcd6b2433634155098d1051314d0a422f42d8d47385e47cf678208b1686e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Connect Screen Infra_Selected.gif
image
MD5: 2bf2552288a6af2851a3e7dc027511bc
SHA256: c7bd1568b0cce7d1e03ae3ebf133a2167c9122859c465e2a715734b56a91bbea
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Connect Screen.gif
image
MD5: 832ad991f5e3e8df4427bec747ee2990
SHA256: 3dcd6af5af874fe1d2c90ad2d5c73ab32cc266ed78c2a1122789d728ec7d184b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Connect Screen Infra.gif
image
MD5: 23ae930bb88df43949bb245c9923773a
SHA256: b23d6fd014f509688d31261eeaa9d724beffcf91cacd30ddb8246a83f7f21f84
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\img\Connect Screen_Inputed.gif
image
MD5: e9682f2ed72c089b4e75a4dc6d63a102
SHA256: 7977cb2f006f8b7d3bb6168fd1c331b5f5fe46cdf33410321763b1d1913dec78
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\tr0300.html
html
MD5: 1156c613e04a96833ab7acf20aaf66c8
SHA256: 17e3903101ed43258388a5ed00991daf32bb6219a66052a4b4a17f10b583fee7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\copyright.html
html
MD5: f2a536a78b50d5d51991aacc6fe5624e
SHA256: ba7bee5d82c95b2e2bfa7951b21e6a196627db0808b09f108f8f93b1a2eab8ec
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\nl\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\tr0100.html
html
MD5: 02fe76af94f02deb7fb6642cdb0af34d
SHA256: c1c4c6a5b3b13de823cdb3a4e65bdc0ac75b6e117e8c36fbca89cacc0b8f0ebb
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\tr0200.html
html
MD5: 44267577f04b1934eac161b2a35b1f66
SHA256: 06260b7efaadcd87cfb5e7e9ef5cc0ef18b9fa2ba19655a89e4a554dfaf63165
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\st0005.html
html
MD5: 27bc7b4c4b2d14f441bbcdccaf12b99b
SHA256: 7be9fb9bb9f0831e7af572f2974d5473bd9c0e6c2564e21cebffbbd454163750
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\st0007.html
html
MD5: f9256cdc143a3e7ceb6a646b153468be
SHA256: ffd61e713070aa9a9af603dd1e55f57bd4ea482ec119909de548e3d3a7586723
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\st0003.html
html
MD5: 97f00eac56b13957cfcefae292d3e9e4
SHA256: 5e9c7e831eacc6892f3cb6238c579e838b4809133a4af89f8c2109c0d3f1c7d1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\st0004.html
html
MD5: edc534a591341e7d8008b3c4dea4c5bd
SHA256: 13fd5b560772f0dc3f0a97b58d5f1024d306d3e43ab3095de59b846938ea9021
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\st0001.html
html
MD5: a3fec565d510c7fb885e232d24bc243d
SHA256: b3d191e71d1658c33e2a300d9ae2ef3442d11acfb25dec734356d9b4d666565c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\pj0001.html
html
MD5: e9d9c2a609bd2502e883046946426e27
SHA256: c2ef90f672dbf117cd7192d315015b7e04d4ae2a4a5f7386bbca1f22b27c2353
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\pj0003.html
html
MD5: 844b203b7e9aaaac64376c1e4f78645b
SHA256: 8ca8c474f839107ed4007a6d1cd03d80ffa2fae98ecef497de23ce3972de549a
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\pj0002.html
html
MD5: 328f4b9a4441a753da17bb99a97b2192
SHA256: a4431c52a083359afd4deaf2cffa03b9be1497f9ead6b923d00c5a42788f21a1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\pj0000.html
html
MD5: 524e99be4c07fdf4951afd4468efe15b
SHA256: 3267c7a43cb1c918d491b59a895d23d0f5bdca4cc040aa5b1a3363bb1ca95b57
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\nwu_help.js
text
MD5: 0222746c07932df03253ee0c1829b8c5
SHA256: c5864b06e9dfccb3ea236eb3d01af42ef7553001324ddffac1fc53ea4499ccfe
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\index.html
html
MD5: 2459f19145283575bdb22f8edd3b55a2
SHA256: ed92dd68a62249337c2ef33cca1377c11cb18fea33a87331d72adb240b9fc67e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Setting Screen.gif
image
MD5: 29dbdfc01b78ea275512c335d237c783
SHA256: 3fa36cc7b06ba76324dceb865e56e392d8703c1dbdf2b0ccca92a1f9a84b76cc
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Setting Screen Advanced.gif
image
MD5: 56be547719fd3e75848630525d07a750
SHA256: 00b4795a9e965889f3b7a99e6a417768f69d6b661a0c8ed5e55bfb7102dc2ce9
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Projection Screen (Play)_presentation.gif
image
MD5: 615f90dff9a566fd1f1549279a85d1d3
SHA256: c6104431af74eea3b8891b44a5038945ec1018851bfff0e8e4fcd5d1e3c53973
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Projection Screen (Play).gif
image
MD5: f9c16bf37bd18f42ad592c5c7861cb68
SHA256: 3cc98206d86ec216e45922abde472d5184aa78cf0c2c693b444f0aad6ea0b974
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\control_panel.gif
image
MD5: 89502eb4f80079fc2f07deb2ef9296fb
SHA256: 377d46ec83edebba00b3d30f85349e9962cf60c150dc352634b17f964535c9a8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Connect Screen Infra_Selected.gif
image
MD5: 704cf4d28c631fb8ae41983ccb540b35
SHA256: 7ba53ef7e4ecd77866dea3a650acd08085f149d705d661d01f3ec6ddcfe63bf1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Connect Screen_Inputed.gif
image
MD5: 46e3da4b53ee0d2d73df525ce9465314
SHA256: 0acf2d6bfab013eef41ceb96ee5f229f7132a8e5acd62362f8bd3117a80524c8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Connect Screen.gif
image
MD5: 56f82373df0f2adb0dd00537d7a07244
SHA256: a09759009a95e61eafb83059eeb5cdbfaee749f2d8b808cd9e422f42ff601e46
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Connect Screen Infra.gif
image
MD5: 47f8c5589359cdb5c7db16763e12f3de
SHA256: 8df5affa52fe77ddf67ea98b8fef16a568a81da633c8d89358e048374c63a5f6
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\copyright.html
html
MD5: 73b18dc7e43c837c75de140658692a72
SHA256: 14fcc0b336e8d1a85d540e294a473eb3ffd72d06433b47ce3de8bfd77f838dbf
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\tr0300.html
html
MD5: 49635db7e6d5e9ecf8e1171301d314c4
SHA256: 899b778c9319779aadfc5e407ac1c9b705d667fed2116a2f69eb5eee7b84ed9d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\ja\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\tr0200.html
html
MD5: 58bb069c777c68df7b82744e02483aaa
SHA256: e8dd04028cd8e5464c33aa8bfd419378a811a0b8279072a67022999c1fd4e957
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\st0004.html
html
MD5: afeb05573814df7189c0643e8aad32b5
SHA256: 9563638918585f1ccf2d994716b944d8948bf1011cce030cf3dc20bd6774497c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\tr0100.html
html
MD5: ef87cbdaa9f1ec64e8e9091349841048
SHA256: d0ed37956276cb00edde90764447da5c9d9536a03d84fad16b4155d2fe2c91c9
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\st0007.html
html
MD5: e5d7d9a9df1da7a97fa786f0ac12f758
SHA256: faa9999d0fb0548912c4c39e135d2673bbb86b047d6356d61d1756974db755a1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\st0005.html
html
MD5: 9f7039285cdce6fd386f381812b13739
SHA256: 98eec58e9a649f210900d8e5b1e90d25a6442e970f760e1b23c24ef08b11db70
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\pj0003.html
html
MD5: 24ae3f3e9762087ebacf55fe20254318
SHA256: 19ebd1f7cef367b134cb50f103d780dfca8a717bde8f11d768b2dc33212ceb1d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\st0001.html
html
MD5: 23df881a910b204c8a87835071e56cf8
SHA256: fcf29756f983ef583d1c96936792f509912dc072a227d6a89ea9fb356f7a0fe4
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\st0003.html
html
MD5: 6e1a8bcf5b92e4d62b4334b56f7d994b
SHA256: 33b83e286a9e025588b15da44fddcd568d5a9a99a1835f8f126adb2214eb8856
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\pj0000.html
html
MD5: e33065697b9611feec6e5be400cfbdde
SHA256: 71517e2ef06028648bf9628e4501b090c2c49e4664c4e14b391138c132ccba40
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\nwu_help.js
text
MD5: 09226bb4be309c0dd9a9056dfac384a5
SHA256: 273c8eac49ec36823a2963c92182554040034ccc903b9f5aea785cc962ffa5bf
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\pj0001.html
html
MD5: a93718c41c7ab709f4031eb9fc6225cd
SHA256: 3808e4a1bac50147e1e994fac749fb1ec645d69e442bc45bc04fd945aa5a1cb3
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\pj0002.html
html
MD5: 82c4172c71cf45ab7c7f6e632870a17c
SHA256: 9853bc9b9496ad7a1e3de2c0381ea111cceb91fea9fa74b4defb1db6c78baee0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\index.html
html
MD5: e5df539ce10e29e08ae235ee3c6f64f7
SHA256: b2fd64c2d9cc48eb557daf011c98518837320c5908a578814ded0b5a147c54eb
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Projection Screen (Play)_presentation.gif
image
MD5: 9fbba0278c60ab8859232b34c893a95d
SHA256: 94bb829e97bcfa03a2948a0e58af81249db28279c43b5d8e7eee5682ac85b870
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Setting Screen.gif
image
MD5: 3ddbc6da2a34b509fde298bfe92970b4
SHA256: e814d204ed0cd914b784d0e83073126a5b363a88967fe1d8b6f12a26fd30dff7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Setting Screen Advanced.gif
image
MD5: da1ebdf35a171bb1b1dbd0b368ad252c
SHA256: db6e8b30efc4dffc68a51245970efc9354a6132d9050914fe0bffae554e8dc07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Projection Screen (Play).gif
image
MD5: 0bef32a150feee9c28321919f623dc7b
SHA256: 24db8c06824bdd900cf845a98b853af47ad72592231c897120284f6ed02723be
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Connect Screen_Inputed.gif
image
MD5: d47fcc31a65c33017863db370aa6756d
SHA256: f730a045744f37ccfaea6d61880d7f1af0bdf43273053fe2b64bf257fe54673d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\control_panel.gif
image
MD5: 362b4874096c5e30a37aa264ffb201d3
SHA256: 9b51a7da22d93e6f546f944d8bc74ffde71d1af2b5a65d08c32c50a544f7e345
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Connect Screen Infra_Selected.gif
image
MD5: a62c2c940924ef8161370c4b547e089f
SHA256: 840ef238a95eabb1874288ec896ba17d6f4f7a5d8801badc423a85f80fd614da
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Connect Screen.gif
image
MD5: 1c25279060c9cb0b0f63e0162d05a76f
SHA256: 123ed7d84b80a2192774969af16828e0b7f4e692bae6dabe46c07641be11c1e3
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Connect Screen Infra.gif
image
MD5: 13437274ce9a6b320da7d24f9349a23c
SHA256: aaf15bcc24d67b75f87c651b66b23f243dcdbba9f070db82f189a427a994bde5
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\it\copyright.html
html
MD5: a16dd201f972ae01c4fd32483ebc47df
SHA256: 0e55831ef50259b27d94b33564a0e9e046829514afb0b43d70dca53dac766fad
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\tr0200.html
html
MD5: c3fd39138bde80cceecdfdeac5050567
SHA256: 43edfa270177139b4258b6603788eeb9febec242e1d766c34ba41320d52602f5
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\st0007.html
html
MD5: 7056328c77ff6843f646d02296540009
SHA256: 8f041f79837b4888f3b8307f2b390c0eb4f6eb443de93677fc0d3c2ac2e6a8c3
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\tr0100.html
html
MD5: 0d7ad722a5aa9c1b05902da56f411a37
SHA256: 2c8115812c5c400128af6a6bf267d6b4ad8922c31d1807edfe9290d0148df9e9
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\st0004.html
html
MD5: ec1032074e0856e45c3c23a465018a1d
SHA256: 1cea8747d35fd492c3b2ad314da1bd1c29560fc2792f37d2d0619c2ac2ec08b8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\st0005.html
html
MD5: 2ac7a536091edbe807bf3e5c3103824e
SHA256: 15386518e80c61d352c757a7d3324a9ee3583cc6e2c77f25cba0c8c197a09897
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\tr0300.html
html
MD5: d5ada24f9a42715841168737b080f38b
SHA256: e6520a8f2ca1dd1d3cb983c124437feef5966a4e04d296c3e12101496bee1e2e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\st0003.html
html
MD5: 2e0ae4046e6a9e7fce0abb0659501482
SHA256: d670ff30567ad16f0b3620fc42b21f2a2ba1288e6af367f8783383d4b1125b43
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\pj0001.html
html
MD5: ca5931e62b656db754aef2732f08c896
SHA256: 0fe5dcac5acad1ab2c868f47ce12c1a85a50b1aa84193a91edf0c159147c7878
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\pj0002.html
html
MD5: 1c56f3204f9a1d3253d56042aefa530f
SHA256: 2f4ac2ca9eab853853d80e73d203dc26ee21c2ae51af28e6177d5c112c955d9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\st0001.html
html
MD5: 642bc0d26e108ddc9dce66dd33a25013
SHA256: b65577bc25f89f835035338ae96d2c80ec0d26226a7bdebd262b4bda66f710b6
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\pj0003.html
html
MD5: da8b0add15b269247ef40b51ceef081f
SHA256: 161d5cd5c33f2a43d4e51e121c654a51c65b0583d7341027438e05a8c6481ef1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\index.html
html
MD5: a49374860877feb58c308b19429e9606
SHA256: 40542f1d1fd1a820123a7a2601b3626f3b37365ff6270f75c24a6f5b0b60c2c4
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\nwu_help.js
text
MD5: 51d8f71a5e061d3fd604daa31733992d
SHA256: 82e1860280fb1685492cb0b623c0c10114a995197421efa887b161409dbc6638
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\pj0000.html
html
MD5: 37048c82da45b23b9c8bcf85f93614af
SHA256: b65f89ec01dee250a0b5c57f12a993c7d511487b628e11de59309ed65e147c83
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Setting Screen.gif
image
MD5: 5865260257b822580170adbafe21fbb6
SHA256: 161ba477bd31e8bf7c262437bc24803bb2d087d577107ad49327fe9be66e6d72
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Setting Screen Advanced.gif
image
MD5: 31f3939aba709f972ffc2fc2036bb40e
SHA256: 0bff3fa707fcd4f5765b116992fe3d81a2f410e3d36f936a3067f56374702182
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Projection Screen (Play)_presentation.gif
image
MD5: 0355b076d1641f5e661df04b2ce419c5
SHA256: 2bc5381124b7deaf2c48751e09e7f21b0f92cc539e7f0cd2bc1a75c3fced91a2
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Projection Screen (Play).gif
image
MD5: c71676300b842fe9edab866efa960612
SHA256: eb37e09d3245c90cfa4cd049907ed6e0b6fd63ccbf54b05c89238371aca11d02
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Connect Screen Infra_Selected.gif
image
MD5: ddc39f0c2d7d06025d9c00236c6b0f01
SHA256: fac0f8ace468cb3bdebf6b468580fa796a89c2ddf9e33741d42f6338c1c1d340
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Connect Screen_Inputed.gif
image
MD5: 82228cea37ad4f27cc59e36fc2b07014
SHA256: 83b7850929c2d9c2588e45151810320d5614268e06cdc1c96d4186de4a67bb6a
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Connect Screen.gif
image
MD5: 016be2113d494c1f4cb3aa1a6cfc8972
SHA256: 10686ce4e4712d163bb5ab3c1481e11e81de31e1abdd56348cda0ae2e4e2cc27
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\control_panel.gif
image
MD5: 1be5ab21224e8ca25496b8b721e8ed5e
SHA256: 4cc7541b4dc909af537dde8a84b4e790fdbd81121452ee1726707953ff8b36f1
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Connect Screen Infra.gif
image
MD5: 6acf613fb58e9a013d63858bee4e8b88
SHA256: 81cf42fa1ff39611ba90c405c2eb32f48bc105dba659954e543e9a12af008c45
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\tr0200.html
html
MD5: 68ec98b9a55ca172264fdb7551a1f035
SHA256: c735dd5864c843f2bb9764790518d34e7010c0e047f2708f55690806ce776018
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\tr0300.html
html
MD5: 60e1d81c3cce728754258019eca8e96f
SHA256: 79f67f88e481ed02d31baada481ed01bfbd993a359a7a79133dba5d111c88960
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\fr\copyright.html
html
MD5: 34e619d37f213c71a2a06fd331750203
SHA256: 18c5cbc556b4c2d94e0452e1557625192e4043f60beb7eabcacd7ca131e6c8c8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\tr0100.html
html
MD5: c938baa48ebe9fabcd64d65c71d95916
SHA256: 53433dec754fe5f8fa04955ae99e36c68f8abe04c24985bf733a6d8fb7baeffe
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\st0007.html
html
MD5: 20e6bb69ec277808ac088da77138a165
SHA256: f74be150b5159ee43483aa31e7929c548e1aaa9d3e555c6404a85496c65b9f12
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\st0003.html
html
MD5: f89e83229732309bfcca255fe614e05f
SHA256: f8247319484f9c4ae23678f8056215ad977df5f95b4f0a0b4c66b590f6881eb6
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\st0005.html
html
MD5: 8f740d14c9eb379f90314dfde721b5a8
SHA256: 835da39a9116fa1637da7d0bec34ebef033fb042056cd06fae92a121d9092030
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\st0004.html
html
MD5: a0cfd44801353974fb608664f379c086
SHA256: cdbbab7012e69f0377822513c4454d607ecfdcf90d02a6a66b9f4514fd48b551
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\st0001.html
html
MD5: bdeb6719de72577f12a51781852e448a
SHA256: 96fe1c4029ba5ddfe97b6a75440bfbb601e872b7cd1f54f80d3cd830659d5b40
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\pj0003.html
html
MD5: 1ebbb03fb934c2eba8db1d1b400a1c04
SHA256: 45432773bf64d9e6b21442fb2d69d5c4b6df34dda9c7a0ea1d350771996e9d80
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\pj0002.html
html
MD5: 344e55bd33896f158ea99e99476472d5
SHA256: 5caea28a2412310a157e5738281518581b67e4947324bca09296489a8455b8fe
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\pj0001.html
html
MD5: 33b80f5d6522d5d64fb6e6e8bb18e78f
SHA256: 49e6e8d2c8abe5ece6640bddba5473d997f4a542f26269bfe84c90f39a302f1d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\nwu_help.js
text
MD5: 86b0ef932daf0f9098b45e15b10f53b6
SHA256: 8481a4cd9ffd39e9ddf3b2a672e69620b480962bd92a7e30e51d1df48a2b74ff
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\pj0000.html
html
MD5: 1e0fb076307d076703d1e311c2f7e1ab
SHA256: d2118f20aa32dcae1a571a33d124dc625b3a744d34e1e2be0d39c0ca2510d334
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\index.html
html
MD5: 35bbf4a9b6d8e87befe8d8725fe3172e
SHA256: f32a805757795c83d5626344e77ad26e5bc3f79805d5e35c2dbc0fa50f8fe231
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Setting Screen.gif
image
MD5: cb9a65b7126a71d0c979de8df292c01a
SHA256: c850aa733de31cc42fa430c751bb6341d73a130556bcad06585ee1154c8deecb
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Setting Screen Advanced.gif
image
MD5: ce3b769844eb65d2374bf48040d56d07
SHA256: 828ceb840ed1cf3c7648092c063d8ba5395bdc626f7cf73881a361c0c9985edd
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Projection Screen (Play)_presentation.gif
image
MD5: 8f05b00fccec36d6daa7708ee301ee93
SHA256: 02c52e74a6d8719c1cccd9adf08bf35baeb9fd3a6eb063c9d685fb472d8bc6bb
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Projection Screen (Play).gif
image
MD5: 9323800447f00ae026e81d81b15c23db
SHA256: eb4f59999d11dc825da5cbc42e88fb435333b732240397c542649a2ed205e46d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\control_panel.gif
image
MD5: b4e4fb5159cabff3f3eaccec5098b066
SHA256: cbd78424eb0405b2f3e6c58ad63e1869eabebc64278a1594f57f4edd5f0ca0d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Connect Screen.gif
image
MD5: f4d6f7f13306324e469b4aa7cbd98139
SHA256: 06f4160106a48d38cfc70e0298eda8ae1a69bb4e07b20e219279eeaa5feb5e5f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Connect Screen Infra_Selected.gif
image
MD5: edd8c5af6885c14c9c552e85e964178f
SHA256: f41fc692be8ccd10dcd35b54406d05cc9ed3d7d18c9d91c9278044631b22aa36
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Connect Screen_Inputed.gif
image
MD5: c24c36ee67d76db5b6476c5cfc9d8d79
SHA256: 17d4442194f86efd1bd3313627bf63ef612b988ca956ed7948c0e76e8916a66d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\img\Connect Screen Infra.gif
image
MD5: 382b6d4762fee65a991c3791b77137cd
SHA256: c129ccdef490196be2299dd6e4fecbf1bbb6bb991e12abd5f417fb85fa90c82a
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\es\copyright.html
html
MD5: c679f54a1b440e6da2bcb264003c4f78
SHA256: c90fc017cf488b1ce94c3b3c74c0bdeeca056dcef99efabb8c7d2f1fb3cc0d38
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\tr0300.html
html
MD5: d5c058598cdfd81e910a32b5969f88ea
SHA256: a4f1d03133b125e188443ee18f3ec24653937ae79137c665b6930f93c39d009d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\tr0200.html
html
MD5: 1b5a3d6ae1a06f6bc0af7f1cd276af27
SHA256: 74b048f155e02486be111556fb64ae74831a44fe7b493e5a275b8374964d6898
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\tr0100.html
html
MD5: e7bf2ae10d793c2f4693860cc46b8efa
SHA256: 9dc93a1b29f4d2e06c8ff27286a2e66318fe23174d0bff924bf92b94c6228a14
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\st0004.html
html
MD5: 67c1d81f0cbde960f78400f57ab12ed4
SHA256: 3d972003e5f9a1e398d17367ace280eb8f31807cfc2071cd0b49b4b5b0caa574
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\st0007.html
html
MD5: f8a39f50e79a3daff7900305687dd793
SHA256: deffec3af9d6ffc465dfd5462dc85cab2e93e0034e00deb6fe0fdd959e036877
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\st0005.html
html
MD5: 81af505f1d421e8ab9706de427e0ea6e
SHA256: a853190a1ee5ffa0a61d5d497742bf0739a0d30db8a74b963b6c6091eef3026c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\st0001.html
html
MD5: fe8452a3321b7b2e8de076851bc905f7
SHA256: 44dbc92795ec4edc2cad11cc4c717dbfb3a64b8cbeead35a693931d072495515
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\pj0002.html
html
MD5: b503d0b86943c3a6b0cf17dfbe1a620e
SHA256: b5733bdaa51355d61f7cf4a137289c68c046b4a045959efc1ff0cafdf68fe837
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\pj0003.html
html
MD5: 825f6a06e0816e7cbed03455fe60afd1
SHA256: 13bc40c2b78eb4efa04f8a2d15fd1828104673d4c28ccf49802938f70d747bd6
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\pj0001.html
html
MD5: 92556587fe14b4ab972a7e6f9433b27c
SHA256: 399f472510f39f2ce678191230ea6dcf6350c4b6a172d1f704ac5cddea14b982
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\st0003.html
html
MD5: 0d7fd2d2a45dc968a5eab1eca2e241a9
SHA256: a2c32a7b44ece24150d768c17f3b951e4bed6f7a514ee791add9909454bd0394
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\nwu_help.js
text
MD5: dab4105ce216f850efb42030b77946f1
SHA256: e8f7ad86a84f438ce17786b4a892b0554071d8454a18195f4a68be7e508aa520
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\pj0000.html
html
MD5: 6561f3f99ac765b097f3ac86e4d13bc5
SHA256: f83132f863f8d8071ad76eb8a9ac7a2afde271e139f07a8178ca8c2ef5cfbb9a
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\index.html
html
MD5: e0fe43e9d1cf73cff757f5b5595e7962
SHA256: 3e2cebe8552d073a867eae8cd34b5d2d7df2e523570e7f28faf5e8b239b006c8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Setting Screen.gif
image
MD5: 18eabe68eab99b4e63aabcda38e6302a
SHA256: d56d01185eb8ebf25c6b56a134f6be40f07398a0ea2b5da16384c36208b58c2b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Setting Screen Advanced.gif
image
MD5: dc015aed2d85046e8b18b0e965b6e761
SHA256: 9a0b3321c5f31d9a236e1daa7b63962a5edd193492e5ba1b5d8b9bc186823445
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Projection Screen (Play)_presentation.gif
image
MD5: 7ba1dc3ba895392795abee9573fe73d5
SHA256: 046ce30cdf7354e72efa75220e575de894c2b1648b63f47896478739bacaaecb
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Projection Screen (Play).gif
image
MD5: b5eb99ad5ffca89eb1c7802b5799854d
SHA256: 8692b53a1832485271708756d36e6a4fe598af9d19e00e528670d8b5f476ed04
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Connect Screen.gif
image
MD5: 1da8fb8dce49e19bf0523874fbe76313
SHA256: c69e7963aaf97c79a1cdc636c46d1d72fb0da61a6f01ca825cd5043afaf12adb
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Connect Screen Infra_Selected.gif
image
MD5: fb885f510c6369bd53d2ce19acebc9d4
SHA256: 2744a6fc812e55e52e9fd3a5df3b9645bdac7cf4bac7e42c9a0fa15826f23959
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Connect Screen_Inputed.gif
image
MD5: f2edbf84e5020f8d8dcc15e7e5ab49fd
SHA256: 4d8e326efaeedede8f95d84a354a036bc1fbee7dfd82ea8d144ae406230aef40
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\control_panel.gif
image
MD5: bdb9e631510ac97aadf6de00e3946b0e
SHA256: 7e7c1c5f1ac123b7fb01e3b00b0bc19679561d68c21599d199061df83641e3fd
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\tr0300.html
html
MD5: 851c933f6d626fe727267b879a7da39f
SHA256: a18c8047f956404d157cd9ff9c2ca1ad6ae4cade57576a95cf80825c6cf855f7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Connect Screen Infra.gif
image
MD5: 1697bd6bab76fc56f3e81b0379e055ec
SHA256: cb33ab3c9388e579a076bef3fb444ddb95153b7e47708c85892d4fe976332c90
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\copyright.html
html
MD5: 55f9c0e010ee5ca95942d805d818384e
SHA256: 23100e5a79e9f607cd5138461b69361426374cd7293bebecbaa7e80410bcc63d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\en\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\tr0200.html
html
MD5: 8e8886dd9cae2d796e0a185a2bb21e9f
SHA256: 9a554216e3dee24dd3a1df98436f299956309251e14f439cefdec2c2f2335d74
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\tr0100.html
html
MD5: 4e1ac4459f334fcd710a0cdbdf9ff952
SHA256: 8c28c6106b7ffa7b19aa5155ce01240e74b8da30497d507b5bc6b04be0ffc39f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\st0005.html
html
MD5: 6d9f29adbd2e62193b1ecfa254c26d93
SHA256: 3bd96b53189ea71b96a275fdc5b35c5ff96cfeef803c3ac0a0f199d11637f8db
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\st0007.html
html
MD5: 3f015eb64cba9fb1020bc6b39210cf2b
SHA256: 2be88b0534dc9290d6d5cc997cffb5cfa29bb40b30e1b386ac871ec8875bfcab
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\pj0003.html
html
MD5: 49c20c6d6dbb5eee187c2e1f0f63aa26
SHA256: 536fc78b8f081fbd94783f7a85f4a78b2ed1ad1f7b01ec5d6ca63879ec81793c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\st0001.html
html
MD5: 3eb4db713b0b242acbf451bb436b1354
SHA256: 30f3c23744233a3dead005b9555251ceb4ce4402e5694bacefcebc8f3cf90c0b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\st0004.html
html
MD5: 11bea698aa139a19ea505434dfa80c51
SHA256: fc1eb933f1fab8dd194006d170bd57ab50f42c4346b51d94286a099db703b437
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\st0003.html
html
MD5: 4c316b96ecdef7b41264f6b2efdcb827
SHA256: a6a231726670b41dccbacb9c1be28eab9c257a8a44170f9627f953de3b03f247
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\pj0002.html
html
MD5: 8e5c78963b6d4d5450d42ffba18d827d
SHA256: eeca7b27a85222d9e3c3dfe7fcb0c6170d4b098682b8c51e37f1b25717fd0344
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\nwu_help.js
text
MD5: bef6485b571d2c8f90648db62d96c736
SHA256: 8665e05a25869eaac4cb3cb54d0bd02fd10e0841c8b812cc13aa5511d5ec7093
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\pj0000.html
html
MD5: 1d0cae36c1ce044559ed6efb707f506a
SHA256: 7dda81459dc7d0db284c15a7dae94daaef2eb3029bb5b5ebb5f47db258a46d31
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\pj0001.html
html
MD5: 6896dea2828f389b3a2786417147817a
SHA256: fc572f2b5875a7f95677657c337aea7f3d5206b17b388f331ef856bb76ad6c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\index.html
html
MD5: 727848f2d0de9dbe849e06f9b19440e5
SHA256: cc53e271c956dcf9cb39fe3dc052f0ab4bdce453e698e4d787278f21ded8e64c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\start.gif
image
MD5: 16f3a209a2b1a36e7f17d144791d3f8a
SHA256: ffd6551df3a45ad929b4d22f4a55761e839379c4d5523f18957c66c6d22972e8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\spacer.gif
image
MD5: 325472601571f31e1bf00674c368d335
SHA256: b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\X_Button.gif
image
MD5: 282147f42fa28b1e52a2abc06239709d
SHA256: 4fd46710332c3d5c4576352a09d8bac9ba76e1bd04955330eeff26aee4c1076f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\RefreshButton.gif
image
MD5: 2c1adcf2520ac51ea6b6dc89f67642f8
SHA256: 2c818a2f94d732be2ab527e2ca6d8b21f0dc2d32b8d5e5da37fd5b8053cdfc9c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Setting Screen Advanced.gif
image
MD5: f955059b8378ec7bf0471e19c34a8d58
SHA256: 6e841343ec165345efce1653b093805c11cd52d15d656f5b7afdcd66d1ca5876
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Setting Screen.gif
image
MD5: 8c7bea96c1f4287e6f6f67abc1ec911a
SHA256: db2e694a51271f28bbc7ec4125a57e9e212bafa5e8ba6707e0e88b8f2c4a8ec9
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\item_name_head.gif
image
MD5: 06059f43a4dbca5feb25dd4f5e523a68
SHA256: 509bd9f318f58ed8c198bf6e21f6d9f1b612945ae2716760dbc6d6ceca305121
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Projection Screen (Play)_presentation.gif
image
MD5: 77f78ab56b7949b205d46120b89c1043
SHA256: 4b187b66cbbdafa9a082abfc04b7ba435a2ca030be8f34ab1a4580a0418d5848
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\item_title_head.gif
image
MD5: ada3e0a3dcd1c5ad3e06e90f49395c70
SHA256: 51ca032cc8d42650405585622d507478cc0566b39caec68a034068a42abce39e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Minimization_Button.gif
image
MD5: 4e0733c655e7585412801688512162c1
SHA256: 15fc85d802e7b4cae49d54b953d3c189c625bf96507e03bc6f814aad6a8177ed
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Projection Screen (Play).gif
image
MD5: c42f62668d53b595500b99ea7f25c97d
SHA256: c06acadb66603cabb8d0642dac3c69c5d423ee4b2e20c0da04acbf6ed56d991e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\homemenuBG.gif
image
MD5: 94a0ed8d052e6d01ed693127b1a7fa95
SHA256: 8a1a383ba883894ef2b9e535adeba5c2d573a38b7139f2e222bb60a76b8d4b5c
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\homemenuBG-r.gif
image
MD5: 8aea786d800fdff0c72932c2894ef858
SHA256: 2ff015287e543bdc1d8a791da268beba224df4a7424307b61b513995da0a7fa8
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\H2.gif
image
MD5: ab9d3b2d8b8062fce82aa5087c7f27b2
SHA256: d38ce030d907c1881e4060637b81252cac81330da7f195248fa5572eaa16b9d0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\homemenuBG-hover.gif
image
MD5: 1c0a20030dd1fd241e8ce849ab6d0814
SHA256: 3940b3122cfa0cb75e04299c799965a01e712e4b7cda37391efa8391fea6c666
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\ExitButton.gif
image
MD5: 7689aaeedb96183ff8978f34bb7c57b2
SHA256: 24ce2a43eb93e9bf308873b64267a18d97076ee4f5c4a799b74889ec65ecf539
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\help.gif
image
MD5: 7c17479e6308bf7ca561152c8ab3d36b
SHA256: a8f52b6ee19802b17cccea5e482d8d0f60a65ee8e0f296f835c36ad1fc57f005
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\DismissButton.gif
image
MD5: 36454f777b22ca089d3bdb7d4d5bd534
SHA256: ddef6f0a482ba77c8ddd4b5aee7aad2bd4d771dd5ff4c4606d30715042418c07
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Display_Change.gif
image
MD5: 3eba5af2644224568b3bb3262d32c44d
SHA256: 69596af1f5433c61e76547c004d988d6283b159be73b29f38c832923716ac22e
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Connect Screen_Inputed.gif
image
MD5: a72119ca5dac35b4f45b2431b80e2d7d
SHA256: 3f680a4a72249173af5e9ab588c97b1ea6bc60900e9fa4d4cba416318f6d5f7a
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\control_panel.gif
image
MD5: 16313c42a2e7b98df20d79fbd2ea13cf
SHA256: 0fdf093409021ba7ff92fae8a4163f20c0c164bfcc251c2c1f5878e552312dbc
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Connect Screen.gif
image
MD5: fdb7518d042b301d4e65f58e81fd2de0
SHA256: 4ff4566ce273981bfb5bde544855aed3364e2796cb6cb5541a20be0fd1656a23
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Connect Screen Infra_Selected.gif
image
MD5: 2a13f1f306cf4ad694a606620da51ac1
SHA256: 5fa348b8157055c69969dba78623b0c0c0574dccac89f81f80a3e51fc9390819
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Connect Screen Infra.gif
image
MD5: 02fe18ae025765ca606103dfe4aac6ef
SHA256: 6df093941c240250aed352600df62bd4fe09b6a2a9107895606993d16681b13f
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\img\Broadcast_On.gif
image
MD5: 161cba61ddd334b3b9bad6369be4f400
SHA256: 311971ba2a3dad6c46910fe2dd82913f0e393a45d694f6bbc8f4240ea51d6339
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\css\wim_menu.css
text
MD5: 43ba05c0fa427139ef2046a092ca7e59
SHA256: e8f9255a9096ef707423c6523b1be193b45839e0b76b71beeb2d1390b12094d7
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\copyright.html
html
MD5: f4d5fcc5d1967e0407c31a4feedfe992
SHA256: d3b93bac145435b266a07dbd1d108fce66042d66d29aece7dc575ffed60b742b
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\help\de\css\wim_help.css
text
MD5: 821970859593ec331c0d357553a0ce41
SHA256: 9941a37220c48aaeab0c1a57ac19cc05b783f6b61c52b40240a86145e72a555f
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\QuickProjection\help.cab
compressed
MD5: 7d68cc90ce9ab83cd7df24a76ae0a401
SHA256: 3d1ce2604ee547aaa344c9ab1508e4cc4476d34200e6191e31c4702482b1367d
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\settings\user_settings_v1_3.json
text
MD5: bc799f389979e4ec637b4e74e5fd2f82
SHA256: 19b301676cbbfe10c2e9e650132fb29bd4fb1f021077810dadaacb9ce88201ea
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\settings\user_settings_v1_3.json
text
MD5: 34e97ab27582b51c6dbc094ab0244ee3
SHA256: 47d6a8c68aad31358bb34521393c8e0a48aa0f74a6d0145eb81c60f03ae1a7e5
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\settings\applog_settings.json
text
MD5: e4be5eccf10c1f3ac8dba123781cec67
SHA256: b8efb2eb33e306f8707d8e5d6662682efe466960e7e9d602b6d0786a73bf61cf
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\_ISMSIDEL.INI
text
MD5: db9af7503f195df96593ac42d5519075
SHA256: 0a33c5dffabcf31a1f6802026e9e2eef4b285e57fd79d52fdcd98d6502d14b13
3212
msiexec.exe
C:\Windows\Installer\256511.ipi
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DFD40D93C719C7191E.TMP
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\Config.Msi\256512.rbs
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\Windows\Installer\{19869367-2771-4855-A985-7A8AFF3F2AF9}\1033.MST
binary
MD5: b359425da4765951f4b91de821adc8a4
SHA256: 0aacae71e365e9d9560091d95a6f3ceffd01f793c9a3dd2e0aeda2cadc4247c0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\log\20181206132104721.cab
compressed
MD5: 6ad6c09af8a61058c121b5d2e6671614
SHA256: eed3f61526c07a6fcaabea702cd4662926257dd69f7eda5ddf0066b2cfa5b410
2140
vssvc.exe
C:
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\Users\Public\Desktop\QuickProjection.lnk
lnk
MD5: bc90e7dacfaec499a3fa754392f10957
SHA256: def8ad2a553c2d9a610ea1d39e884afa0f8f723b294984ee2ddbd7b6152c0ba7
3212
msiexec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ricoh\QuickProjection\QuickProjection.lnk
lnk
MD5: 7beb69522a248b6acfc50e9cdea7922f
SHA256: 9b1994673fe57523292257f692c0b019de5d29a09ab673277069ad70ebc38e46
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cab4A8.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cab4A7.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cab4A6.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cab4A5.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cab4A4.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\log\20181206132104721\app_20181206132104721.log
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\Windows\Installer\MSI6945.tmp
binary
MD5: 140d4f2cff7e9c3d36561af05a7af982
SHA256: ad4285c9123bc2d139681aebf7c8d91de1ac3e377d4e75bd502545d11a873f04
3212
msiexec.exe
C:\Windows\Installer\256511.ipi
binary
MD5: 5ff98b303e7302dcd055b13916e40ca4
SHA256: c3b7b3f39ab1abd13224d0aaf6c90bf3770feb196f86a45a35476dbfd213c2d9
3212
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF20A8B4A5467291F5.TMP
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\Windows\Installer\256510.mst
binary
MD5: b359425da4765951f4b91de821adc8a4
SHA256: 0aacae71e365e9d9560091d95a6f3ceffd01f793c9a3dd2e0aeda2cadc4247c0
2308
QuickProjection.exe
C:\Users\admin\AppData\Roaming\Ricoh\QuickProjection\log\app.log
––
MD5:  ––
SHA256:  ––
3096
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
text
MD5: a27eab95b57e9dbea7c33214aa6b76fa
SHA256: 1d113ba2e21390299b04fdbd29f71a297fdc4a8e2332ef222b2eea9dedc136f2
3096
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 0f7f23d1a2bfd0a1b25a7f4f3937f764
SHA256: 82a46cfc9d7931c540a3f705a280659be7063cf56f656fa24b58f9575e149b8d
3096
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 689e7ed2405a29916fc3fdbcb0109ff0
SHA256: 5db9e7abe30c4c3c8b20840487b2b029aef16c57247129fc7716b82eb9f465aa
3096
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 98eea18363b6363f0037f783813230eb
SHA256: 6bb1d3c75a501d7e4eefd2476da1366246461366cc942d451d8a7a69080eaa0f
3096
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 392c8c332953b48ceedda1d15408ffb6
SHA256: c9ad426aaca74be7c84f99fd2eea44851cf80f483917bf3f4827bbb6dbf4ba34
3096
DrvInst.exe
C:\Windows\INF\setupapi.ev1
binary
MD5: 19c89675516f5d429445450892f16d08
SHA256: b8042c4aec943bfeb907841b177dfef0f10adf9826ba790bcd0dfd81088b659c
3096
DrvInst.exe
C:\Windows\INF\setupapi.ev3
binary
MD5: 76dcc60f78b3dff1ae3627619074f465
SHA256: 18541ac1875315c4f9eff75050c574faff83717c029dae6b366f9c6c3f0c19e0
3212
msiexec.exe
C:\System Volume Information\SPP\metadata-2
––
MD5:  ––
SHA256:  ––
3212
msiexec.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{21453340-1c0f-4337-87e6-e33a5f735d20}_OnDiskSnapshotProp
binary
MD5: 01148c8d11a77033204e38959d5d50be
SHA256: b4084497d553fe60e57bf07cc9149309ab48315b125583e3182b49161528b523
3212
msiexec.exe
C:\System Volume Information\SPP\snapshot-2
binary
MD5: 01148c8d11a77033204e38959d5d50be
SHA256: b4084497d553fe60e57bf07cc9149309ab48315b125583e3182b49161528b523
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\cabFEF1.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isFCBC.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\_ISMSIDEL.INI
text
MD5: 6240cbb1df45908ada012fe71ca44ffc
SHA256: af22ab1118ba80cbf30fbebee9ee6504a4e5792fe216ef5cdb0ee0247c389065
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\1033.MST
binary
MD5: b359425da4765951f4b91de821adc8a4
SHA256: 0aacae71e365e9d9560091d95a6f3ceffd01f793c9a3dd2e0aeda2cadc4247c0
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isFC8C.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isFC5C.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\~FC5B.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x0411.ini
text
MD5: 3f032cddf023332ea5bbcb114bde639c
SHA256: 096a8afeeb43dc7bc3aa6a885ff62cd40af6ccb061f9f5cdd1f3d5a4046930dc
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x0410.ini
text
MD5: d51f1a34dd4e06eedbcc3cb50bb2fe59
SHA256: 9d24f3a2ec9fed4306d10a57798718a37a4e25c5c5589617e862f714977647a2
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\_ISMSIDEL.INI
text
MD5: c8dee7be8ef091641b974ff9ea5afa70
SHA256: f688a5331fde355debf6eecef92735bf750441a410b224c61ede7b6d4ce88ebd
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x0804.ini
text
MD5: 540efa26a22ae3b63e44646df21df262
SHA256: bd0005fc528582cc0cf3151ba04f4190fc0e7f3a58dc7a8fdeec984762cfc7a7
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x0413.ini
text
MD5: 1b9945f4b276f4a0eb278161e1aaf4fb
SHA256: c1cef84a41543af54d21c8c9c0304816df110fe4bf66ff61cb78efe6958b6ed5
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD838.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD837.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD826.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD836.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x0409.ini
text
MD5: 36affbd6ff77d1515cfc1c5e998fbaf9
SHA256: fccc7f79d29318d8ae78850c262bac762c28858709a6e6cf3b62bcd2729a61e3
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x040c.ini
text
MD5: 59fc826435bf134b6d8419e0398bfee6
SHA256: a64cd08c409b4c4fd5c7b802124ed331a29fdbe25162e7019b5ad2fd4dba388b
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x040a.ini
text
MD5: f507df06c1aba3b613dfab9a35e3a1b9
SHA256: 5064fca897118c445aa87753a36fe5f493b45fcba317b1ce5cfca97ad55a7ae4
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\0x0407.ini
text
MD5: 24c0525fb3e964776a84f8939d206656
SHA256: fa297aac13a7664c2a732a99cd2a91624f355b490155ce65152fbd3776fd7b43
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD824.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD825.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD823.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD812.tmp
––
MD5:  ––
SHA256:  ––
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\{BD343DB5-63FC-43A3-82C1-0D442A34B730}\Setup.INI
text
MD5: e784828a35dca793235af04f4f0d06da
SHA256: b55b088e8a4c2a985029b77d3425831a73ceaa6ec8cb0605674eac94cef48abb
3824
setup.exe
C:\Users\admin\AppData\Local\Temp\_isD811.tmp
––
MD5:  ––
SHA256:  ––
2308
QuickProjection.exe
C:\Users\admin\AppData\Local\Temp\~DF030901B723450DA2.TMP
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.