IOC Report
Kor-1.3.5.0-Setup.exe

loading gif

Files

File Path
Type
Category
Malicious
Kor-1.3.5.0-Setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Config.Msi\4425bf.rbs
data
modified
C:\Program Files (x86)\YSI\Kor\1.3.5.0\AttachedCommandBehavior.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\ControlzEx.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Data.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Map.v14.1.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Mvvm.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Printing.v14.1.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Charts.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Core.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Docking.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Grid.v14.1.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Grid.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Layout.v14.1.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Map.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Printing.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Themes.DXStyle.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\DevExpress.Xpf.Themes.Office2013LightGray.v14.1.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Fluent.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\FluentMigrator.Runner.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\FluentMigrator.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\FluentNHibernate.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\GalaSoft.MvvmLight.WPF4.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\HibernatingRhinos.Profiler.Appender.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\ICSharpCode.SharpZipLib.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Iesi.Collections.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\InTheHand.Net.Personal.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\LiveCharts.Wpf.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\LiveCharts.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\MVVm.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\MahApps.Metro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\MathNet.Numerics.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Diagnostics.Runtime.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Practices.ServiceLocation.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Practices.Unity.Configuration.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Practices.Unity.Interception.Configuration.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Practices.Unity.Interception.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Practices.Unity.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Win32.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Windows.Shell.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Microsoft.Xaml.Behaviors.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Moq.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\NCrunch.Framework.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\NHibernate.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\NModbus4.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\NSubstitute.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\OxyPlot.Wpf.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\OxyPlot.Xps.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\OxyPlot.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ploeh.AutoFixture.AutoNSubstitute.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ploeh.AutoFixture.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\PresentationCore.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\PresentationFramework.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\ammonium_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\barometer_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\chloride_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\ct_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\depth_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\do_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\fdom_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\nitrate_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\orp_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\ph_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\rhodamine_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\total_algae_bgapc_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\total_algae_bgape_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\total_algae_chlorophyll_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\turbidity_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\uv_nitrate_cal_instructions.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\uv_nitrate_cor_instructions_step1.html
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\uv_nitrate_cor_instructions_step2.html
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\uv_nitrate_cor_instructions_step3.html
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\uv_nitrate_cor_instructions_step4.html
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\uv_nitrate_cor_instructions_step5.html
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\Documents\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\Icons\Kor.ico
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\Icons\YSI_icon.png
PNG image data, 32 x 31, 8-bit/color RGBA, non-interlaced
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\SimpleInjector.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.AppContext.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Console.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Data.SQLite.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Diagnostics.DiagnosticSource.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Diagnostics.Tracing.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Globalization.Calendars.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.IO.Compression.ZipFile.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.IO.Compression.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.IO.FileSystem.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.IO.FileSystem.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.IO.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Management.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Net.Http.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Net.Sockets.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Reactive.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Reactive.Interfaces.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Reactive.Linq.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Reactive.PlatformServices.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Reactive.Windows.Threading.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Reflection.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Runtime.Extensions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Runtime.InteropServices.RuntimeInformation.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Runtime.InteropServices.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Runtime.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Security.Cryptography.Algorithms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Security.Cryptography.Encoding.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Security.Cryptography.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Security.Cryptography.X509Certificates.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.ValueTuple.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Windows.Forms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Windows.Interactivity.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Xaml.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Xml.Linq.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\System.Xml.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Trackerbird.Tracker.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Trackerbird.x64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Trackerbird.x86.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\WindowsBase.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.AvalonDock.Themes.Aero.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.AvalonDock.Themes.Metro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.AvalonDock.Themes.MetroAccent.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.AvalonDock.Themes.Office2007.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.AvalonDock.Themes.VS2010.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.AvalonDock.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.DataGrid.Themes.Metro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.DataGrid.Themes.Office2007.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.DataGrid.XmlSerializers.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.DataGrid.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.ListBox.Themes.LiveExplorer.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.ListBox.Themes.Metro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.ListBox.Themes.Office2007.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.ListBox.Themes.WMP11.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.ListBox.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.Themes.Metro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.Themes.Office2007.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.Themes.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.Toolkit.Themes.Metro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.Toolkit.Themes.Office2007.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Xceed.Wpf.Toolkit.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Common.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Common.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.IntelHex.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Common.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.DataAccess.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Domain.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Domain.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Handheld.HandheldAccessor.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Calibration.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Calibration.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.ConfigureHandheld.TestsUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.ConfigureHandheld.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Deployment.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Deployment.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Home.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Instrument.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Instrument.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.LiveDataView.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.Sites.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Modules.StaticDataView.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.SessionDataFile.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.SessionDataFile.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Wpf.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.Wpf.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.YsiPAdapter.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.KorExo.YsiPAdapter.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Localization.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Localization.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.ReactiveExtensions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Serial.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.TestUtilities.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Tracker.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.Wpf.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Bluetooth.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.ComAdapters.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.Common.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.DssHandheld.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.ExoGo.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.Handheld.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.Sensors.Par.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.Sensors.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.Shared.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Commands.Sonde.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Firmware.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.InTheHandBluetooth.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Network.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.Serial.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.YsiProtocol.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Ysi.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\de\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\es\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\fr\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\hu\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\it\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\nunit.framework.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\pt-BR\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\ro\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\ru\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\sv\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\x64\SQLite.Interop.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\x86\SQLite.Interop.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\1.3.5.0\zh-Hans\Xceed.Wpf.AvalonDock.resources.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\Kor.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\YSI\Kor\Kor.exe.config
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\YSI\Kor\Manifest.xml
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kor\Kor.lnk
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
dropped
C:\ProgramData\Package Cache\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\Kor-1.3.5.0-Setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\ProgramData\Package Cache\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\state.rsm
data
dropped
C:\Users\Public\Desktop\Kor.lnk
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
dropped
C:\Users\user\AppData\Local\Temp\Kor_20240423082129.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Kor_20240423082129_0_Setup.log
data
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba1\BootstrapperApplicationData.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (443), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba1\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba1\logo.png
PNG image data, 32 x 31, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba1\thm.wxl
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba1\thm.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba1\wixstdba.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba2\BootstrapperApplicationData.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (443), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba2\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba2\logo.png
PNG image data, 32 x 31, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba2\thm.wxl
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba2\thm.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.ba2\wixstdba.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\.be\Kor-1.3.5.0-Setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\Setup
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Kor Installer, Author: Xylem Inc., Keywords: Installer, Comments: Kor is a registered trademark of Xylem Inc.., Template: Intel;1033, Revision Number: {5E63D5B7-ACED-4DC0-88E1-AE3C2AC512D9}, Create Time/Date: Fri Jan 20 17:29:50 2023, Last Saved Time/Date: Fri Jan 20 17:29:50 2023, Number of Pages: 100, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.9.1208.0), Security: 2
dropped
C:\Windows\Installer\4425bd.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Kor Installer, Author: Xylem Inc., Keywords: Installer, Comments: Kor is a registered trademark of Xylem Inc.., Template: Intel;1033, Revision Number: {5E63D5B7-ACED-4DC0-88E1-AE3C2AC512D9}, Create Time/Date: Fri Jan 20 17:29:50 2023, Last Saved Time/Date: Fri Jan 20 17:29:50 2023, Number of Pages: 100, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.9.1208.0), Security: 2
dropped
C:\Windows\Installer\4425c0.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Kor Installer, Author: Xylem Inc., Keywords: Installer, Comments: Kor is a registered trademark of Xylem Inc.., Template: Intel;1033, Revision Number: {5E63D5B7-ACED-4DC0-88E1-AE3C2AC512D9}, Create Time/Date: Fri Jan 20 17:29:50 2023, Last Saved Time/Date: Fri Jan 20 17:29:50 2023, Number of Pages: 100, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.9.1208.0), Security: 2
dropped
C:\Windows\Installer\MSI2A51.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI2CB3.tmp
data
dropped
C:\Windows\Installer\SourceHash{53E0FAA0-9538-4877-97AB-25EF3F737367}
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\inprogressinstallinfo.ipi
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\{53E0FAA0-9538-4877-97AB-25EF3F737367}\Kor.ico
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Windows\Temp\~DF16E3B39B72A08DAA.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF821FA4D0E71BA838.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8D46B7942AD50FD3.TMP
data
dropped
C:\Windows\Temp\~DF9520492B08F72997.TMP
data
dropped
C:\Windows\Temp\~DFA47FD7EBC51B658D.TMP
data
dropped
C:\Windows\Temp\~DFBF8F678D0B571DE7.TMP
data
dropped
C:\Windows\Temp\~DFC0DCF60344CE2CAB.TMP
data
dropped
C:\Windows\Temp\~DFC717440EEDB77250.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFCBBE4D32D2A9F1E5.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFF7409FB5F2F91429.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFFC6DB5678BC5523E.TMP
data
dropped
C:\Windows\Temp\~DFFE467E3852296572.TMP
data
dropped
There are 234 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Kor-1.3.5.0-Setup.exe
"C:\Users\user\Desktop\Kor-1.3.5.0-Setup.exe"
C:\Users\user\Desktop\Kor-1.3.5.0-Setup.exe
"C:\Users\user\Desktop\Kor-1.3.5.0-Setup.exe" -burn.unelevated BurnPipe.{4C76BB18-D643-46AC-B29F-8C96F4C6DDC8} {498B697F-8CEA-4946-9F22-28FC8D89DBCC} 6372
C:\Windows\System32\SrTasks.exe
C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\msiexec.exe
C:\Windows\system32\msiexec.exe /V
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding 701DD997AD27E1C9A69425AFC0186725
C:\ProgramData\Package Cache\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\Kor-1.3.5.0-Setup.exe
"C:\ProgramData\Package Cache\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\Kor-1.3.5.0-Setup.exe" /burn.runonce
C:\ProgramData\Package Cache\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\Kor-1.3.5.0-Setup.exe
"C:\ProgramData\Package Cache\{9217b7d9-4734-4961-b8b7-5763fc11b75e}\Kor-1.3.5.0-Setup.exe" /burn.log.append "C:\Users\user\AppData\Local\Temp\Kor_20240423082129.log"

URLs

Name
IP
Malicious
http://beta.visualstudio.net/net/sdk/feedback.asp
unknown
https://simpleinjector.org/depr1
unknown
https://simpleinjector.org/diagnostics
unknown
https://simpleinjector.org/dialm:
unknown
https://simpleinjector.org/ovrrd.%RegisterCollection#Container.Options9AllowOverridingRegistrations
unknown
http://schemas.xceed.com/wpf/xaml/listbox
unknown
https://simpleinjector.org/lifetimes#scoped
unknown
http://tinyurl.com/pegtw57
unknown
https://github.com/AutoFixture/AutoFixture/issues/475
unknown
https://simpleinjector.org/diadt
unknown
https://simpleinjector.org/diasc
unknown
https://video.ysi.com/ysi-university-exo
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://wixtoolset.org/schemas/thmutil/2010
unknown
https://simpleinjector.org/asmld
unknown
http://validation.identrust.c0m/roots/commercialrootca1.p7c0
unknown
https://simpleinjector.org/coll1.
unknown
https://simpleinjector.org/diasc3
unknown
http://blog.ploeh.dk/2010/08/19/AutoFixtureasanauto-mockingcontainer
unknown
https://simpleinjector.org/diadt:
unknown
https://simpleinjector.org/locked
unknown
https://simpleinjector.org/one-constructor
unknown
http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
unknown
http://or.water.usgs.gov/grapher/fnu.html
unknown
https://simpleinjector.org/diaal;
unknown
http://metro.mahapps.com/winfx/xaml/controls
unknown
https://simpleinjector.org/diasr
unknown
https://simpleinjector.org/diaut
unknown
https://www.ysi.com/products/multiparameter-sondes
unknown
http://schemas.xceed.com/wpf/xaml/listbox/themes
unknown
https://simpleinjector.org/diasr4
unknown
http://oxyplot.org/wpf
unknown
https://simpleinjector.org/diaut8
unknown
http://schemas.xceed.com/wpf/xaml/toolkit
unknown
http://www.codeproject.com/csharp/sets.asp#xx703510xx.
unknown
https://www.ysi.com/kor-software
unknown
http://tinyurl.com/lg38t3g.
unknown
http://schemas.xmlsoap.org/wsdl/
unknown
https://simpleinjector.org/diaal
unknown
https://simpleinjector.org/dialm
unknown
https://simpleinjector.org/diatlD
unknown
http://www.codeproject.com/csharp/sets.asp
unknown
https://simpleinjector.org/diatl
unknown
http://info.xyleminc.com/YSI-KorEXO-Feedback.html
unknown
http://appsyndication.org/2006/appsyn
unknown
https://www.ysi.com/File%20Library/Documents/Guides/EXO-SmartQC-Handbook-E135.pdf
unknown
There are 36 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore\Setup_Last
AoACAPIError
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore\Setup_Last
AoACAPIResult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore
SRInitDone
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleUpgradeCode
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleAddonCode
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleDetectCode
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundlePatchCode
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleVersion
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleProviderKey
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleTag
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
EngineVersion
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
DisplayIcon
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
NoElevateOnModify
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
QuietUninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
Resume
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
{9217b7d9-4734-4961-b8b7-5763fc11b75e}
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
BundleResumeCommandLine
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{53E0FAA0-9538-4877-97AB-25EF3F737367}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{53E0FAA0-9538-4877-97AB-25EF3F737367}
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
Installed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
RPSessionInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9217b7d9-4734-4961-b8b7-5763fc11b75e}
Resume
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppGetSnapshots (Leave)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Enter)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
SppEnumGroups (Leave)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\4425bf.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\4425bf.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB408AEAC70406444B3BBD4163B6467C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A3FD2457C100454BB41586D1CDE7695
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C31BFBFA9972E1488A397264747D8B2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82EE8E6A975136741A0BAFC917392AD2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\454C1C4CA0C29CA44906F4BA31C7B3F9
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED58658AC9726CD4BB07BBDC6832AEE1
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACA523BD564479A4A8E471BAB2FF4D12
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE2BA9EC2BB77704DB72E38AD61698C3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3A6791BBEF3B2E4DB2B2666131C86D2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CAFF723704F7D64E9444EA5B68FB384
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA27EA621E944CD44B915A8916B93CFD
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30CD7B88C028BC940845055F4140504D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\35CCD0985BE4A924EA4AD36B53DAC706
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C44D817E0086845479CDD6E52100A040
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A315762C979FE914B9447FD5860FA41C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BDECD8E3117590F4FB8ED81DE0D314A3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7AAF7F914D9344F47B115F1B197D52DF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B204495369D363B468A42441427E26A8
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE875E004A8B71F4C9193149F440CF97
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6FCC44DF2E6272747885E299900A5A1C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31DB7058A7077624D92269D17378B9AF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE37EE757B1002247A9C1950D9F81B96
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F40F700166E7EF14EB0F063A60AAEA0F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E510A38274C74A04FB6F22F79917B0DA
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE5AA4D1A211E34490185967CEAD7B0
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73D5B10B5A3B0914BA264463BA1F2EFF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9D07F0356E098A4A8E9DA4B4EA10EFA
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A129E3BAFDA70374BB466B04BBCB35D5
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7E9EE105418ABA418412A6F9379208A
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E36BE0B34769C940801387FF040073E
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\52026051B8B53B049AA85BB302C425CE
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91CBF6AF0B12F17459FDFFC7C519E526
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38E6715486D860248985C77EEF869240
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C5DF3341B7B0744D8008F1604C8C44C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD92526D865F71C4A9684332395720F7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D050D6A685AA1864B8B1EA4CA687F254
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B7E9C21786D4784185BC3D1066F7F9F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\799EB02E2F14D9541A0CD733F69FF4DA
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\54E6AA30106CEB0479C99DAB558F2668
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\718DDA8AC8BC97B498309BC4FB16CFE3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1286A9B9CD72AA46B3ADC5957162F28
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E313D8701C441849B689D7D4984A837
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\59A3D400316266840920042AE8EFBFD2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9873D1976049C814395DCEAEADB38D65
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EEEE2FEDCDF0F6C4F802FA1765CE3590
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E2FBAED0E370C1044857E23C165275E1
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F705E29347E35C14D8AC4FE60C6858A4
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44DEA0726C8D8D84FAD3FEF38F46D138
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\859B0ADFD3532E24E8831D463ACC7187
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\11859C6C1980F99449102BB1A763AF85
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3F2FC10616DED0B4484DD1EE4E9E9F4F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\62C7D75C22F90174E919CBDA7D08E4B5
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D12DA257549E61D429598BDD8B732BC5
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7BA4D1A300C0F2448AC0F26E587477D3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B5E2CE71118AA14AB25411C76F8A4E9
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D0ECF0DD41AC0804E8196BCCD6BDB764
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4DE28313D32EFB4CA5D2FB1CAEB50A4
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47C45CBB1BD5A994A9C4A9C756C1CAFC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9587CA4BF65346C4E9C010A519DE112C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9723D6140AFD32C47863D512CB205B51
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EAB9F72C165B6774DAFA6B5DBE9C01CC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\951160096D4B83041971CA3E7B475020
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\837781972C719BC4583DBA9239C5AEF2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F729125300252A4D99A8E60845C7589
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6861737A26759A14DAAFDECC76C28DF6
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A75C29CA117BCD148BD06C3A1DB14B1F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80948B7E864EDBD4887D8D5E93F13AA8
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D01A7EC7FCBB2D7409383F185308FBBE
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3BAC1528D71E224FA1F4269CED6562A
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A09EE3301F68B244DAD2AACBF9BDF2F0
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7AB910DA5834C33488A931BC38DCC6A5
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C969672FFD29B244B8A911EEB384DC19
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80E3BE82C8A91014E9DB9AFA2FD8CE81
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61E0F1AD597E0DE4D89D72D8A8704A78
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDC660A1447C94D48AC5CFDC7F662380
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA0074A79F2A17841A35F661D5AF97A4
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\11BD29C7C7A82794F9FC4E6BBF469CEC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF97806A8E506364D98EE2E980D59608
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64D4F191B5F1E1A448CC38BA5A7B0D11
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FFECA1C66492B941A9EB9CBCE308BB3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E9CFECA72D2DD943994B9730EF6D798
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A260BE09E9DAF3499D72FA9057D5526
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5E5BE50348A19B148998CF0614989CA0
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DB708C28AF97844DAC17C5C44EBEB72
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F04DA93ABD084914B916ECDCE96926D3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA58287C9BA0FC549BB72E827FB869CB
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8FDEB8ED08527D8479232E151EDA9DBB
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61377E73B39D0F443AB0619CAFBF159D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\802F21A011F65DD4EB94D49D895EB3F9
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C8BA29426A44F841AB9CDB29FC2BCC7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8C2149447DEE1144B1F5C9D352A4435
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE51DCAE5E14EAF47806ADF4F6B9412D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE9B9A40F44B0674D90D0C85D18C1B8F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\509D6E4451318714BB321160E21081EE
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3F275C95AD748E4ABFED2744EF8FA6D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08977EFADBC8DB44DADAFD5529EF6932
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C8FA36BAF33975458A84B4B2055B811
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F27EE45D03F446438D67F75B1A088C3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8A7F8979D4C1CD342AE35EE5700334F3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1BB0C46719EAD5240A80E73C99EC0EA9
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\425A3037C3286814BBB16C18270DE7D1
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43D16BDB11789C6418B1B23B2018305B
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7A320F680CA0FA448E1919FD31466B1
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78D07BA6E3006D6418F113B0E007D688
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E246CB82EF3A47428244B68144B8FBF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E71DCC599AAFE0D4B8F6F63318F6BE08
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C3338CCD097F2B43AA558A72FFFF11B
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1EF468110F4007842BBB034960D83FB4
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA5D0B4A9437ECF41AB3E037ADD6FF45
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7636975CE053C746AE1937718AD8DA6
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CAE41C02515755043858395ABE421973
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EDE131B70244AC41822284E5E3141BF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41842BE40B1CBCE45B01C280FE3DB6FC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B7A30A543D5E0874AA571F3711384DEF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D78A9921EC82124DA332E88FCAC6155
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFB618866E4487E4587F95A6D5E0CECC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D0327776E494C8B4FADD776DA8CADB02
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9AA10B8F9C4131647AC1E177530115BC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08C26D6C63A7E624E85FEA32CC6E0B3D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DECAD03FCF0B1A4688726E47FF56D40
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\961D22DC156FC834B9488156E314485C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4BA0272B62534A469C91D6D85A55492
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5011F06052EB3FA4E8E8316E0BA6351F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4358DE1781BD20642929561C540279EC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23F0E313B3C3D8944AD2D4FA386B8A67
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\064A946ACCFAA534A92646B1A82B7D4B
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74532025809A69D4FA47B18410776156
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\95C4A25D4FE67B64694B5647E80F9B15
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3EEFE0F9323BE942AE3E81223B44DB8
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC25BBEBF4B77B748955E61F643C3139
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\13AEDA6C452AA194C8D06E8A150AE523
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0F6764DEC3B46D44A8E6364EFDA8F177
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F984FD98D422D8D4B98CCFF8C1318970
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3300AF7C9717D00498F400C4BB0C882F
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9AFCED27B01E8E43824F8F851C9C0C7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C115A79833AEAE946AE95E839C9872BF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4D51C738E3A33F4408817592613DC134
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDB2DC526FFCD4C41864F42100FBB68D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DFEB0027BDEF834787017FB3B338945
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\40C3F3D133DD6804F881039E7D134DE1
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C587D7C995A19E24E97A884E35C085AD
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\63D1C86132524B7468E0DC1DEF3B8286
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C585A8DAF25A26642A63A4DC2FC72AC9
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FA79299597A61047A9108B493A5C42E
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D10A5AC162C17EC4B92AA5B078C6BB07
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED4147CD7F795594F8A4F58A37DD0D17
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19278569B22D6224EA4CE0AAD6BE8FC7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3FB4B4E801BD20498AEA3EA46F90949
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80185BA16E9BC5D4087C5A63C80463CD
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19758E8D0722A354AAD01094AB61491A
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6579B527132C336458C62B47D3809152
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E8D8CA67369414FA553F18619295CB
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DA16E786D888904FBB0077EBEF9F6FE
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C66520629C4A8364EA768D56AA2E5451
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D36FB97611FE514ABFA164A5813794B
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DBB6158E063E8F4AB944F8F2BE84510
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7031C3F5FBF3B704993403F7C3365F06
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CD7F97E16DFED3342AE8FAE8EDBD0D19
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\722AB872D35539B4189A6F4775C147A2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4458C94A9C5831E4FB7F39928AB600E3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\92791228EEEE3EA459ED4774F036D311
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20E35783836FF1A4C9189A293DC99888
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4284DC0EDDAC2B4B9BD250346D69030
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E8271065FE1EAF4B8CCBF898BC0361E
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\744F27D27F8F4EE4BAD52E59D2E3E327
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DF868C8B341B80408B50695090B62F6
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2C3CADB75EE2ED743940A10B62CC4133
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E14D269BD6F9174E9B85B93548640DA
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F4D9C68C89F8704E83B0FA2DA716D97
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3D6451150BC30E740B8FBB50D6294FA5
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8FFB31039E72F29409668AE1787FD74E
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30516A27A82E36F4D8A96738D0D324A9
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DA44344F12441EC4D8F1E9BE6BD21318
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\63E1E505FC0286E41879B9E663BAD596
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8EB5F755D9D4582438F7E296B401F4F4
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8356A01DAB4DD8747B0F4C6EB1588AC0
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C005573052DF6BE418896A645BAB99F7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2829691E9F2989C4FB4DA068F42534DC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\429E3A0D2841AEE40AD9F34B0EC9D609
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EB787DCAA5ED20D499E5B26DEF142C73
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F21B9BEBC9BFB6C45A7AB24A34FE807C
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C03472CC6C274764CBF3CC6682F90AF2
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\21F36CA1B71177D44A8EDE797958CF0B
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE47BBB4BC3EF8C4D8EE6C4ACF7E4267
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\547C331AA28FD5D42AF129AD8BA8FF20
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\884DEE4238ED2DC408A19F6BA9EE23CD
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F9CED3558A2C0C45B8B98ADADEE03B7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AC00527DEB949840A0B93DCEA2AAF88
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1552F3F482241984087B5569C94A6DBB
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DC508CF53A46A949B240741ECD7FD45
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D8AA5C82C19F3FC4DA0800966C9CA984
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E070B8B248B0B14BA1981578B56075A
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2CAB0EB152F6B2341A44BDA47D1940D3
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53E2FC88F3F4809418787B40071D3CDB
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60658DE905506994D80DC8020EBC5DEC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4ED7EAF477291854DA40924D2779E232
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DB88C20B85F40E41B43E10C493E2768
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB3E056D9E8895C4A9414519A9BE06BC
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C96543BA22A35645AC7FC26F2AA836D
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ADDB88D210A2CED49B3913F8269C6832
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20C7DBD7685E51B45A8371278C0E6B22
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA5FF41D18553E24EA9792F428761905
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\096388712C226C04A84160FD81DDE2DF
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9F91904ABBD6E6B428EAE89220C8C4F7
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\DefaultCalInstructions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\sv\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\Icons\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\fr\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\pt-BR\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\es\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\ro\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\hu\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\de\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\zh-Hans\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\x86\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\ru\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\Resources\Documents\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\x64\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\YSI\Kor\1.3.5.0\it\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{53E0FAA0-9538-4877-97AB-25EF3F737367}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kor\
HKEY_CURRENT_USER\SOFTWARE\Xylem Inc.\YSI\Kor
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
LocalPackage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
NoModify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
NoRepair
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
SystemComponent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
Language
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
NoModify
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
NoRepair
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Size
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
SystemComponent
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Version
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\8589AD8E6E7D19F41B532DEF307F7CFD
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\InstallProperties
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53E0FAA0-9538-4877-97AB-25EF3F737367}
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\0AAF0E358359778479BA52FEF3373776
Kor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\Features
Kor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AAF0E358359778479BA52FEF3373776\Patches
AllPatches
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
PackageCode
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
Assignment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
AdvertiseFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
ProductIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
InstanceType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
AuthorizedLUAApp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
DeploymentFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\8589AD8E6E7D19F41B532DEF307F7CFD
0AAF0E358359778479BA52FEF3373776
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776\SourceList
PackageName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776\SourceList\Net
1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776\SourceList\Media
1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776
Clients
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0AAF0E358359778479BA52FEF3373776\SourceList
LastUsedSource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
There are 457 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
36B0000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
2DDC000
heap
page read and write
1EFBFDE3000
heap
page read and write
1007000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
370A000
stack
page read and write
1EFC1780000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
3430000
heap
page read and write
1EFBFDCE000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDCD000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDE5000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDCD000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
D98000
heap
page read and write
1EFC1D30000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
2F30000
unkown
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
3100000
heap
page read and write
3D4E000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
2D44000
stack
page read and write
1EFBFF70000
heap
page read and write
5D8000
unkown
page readonly
1EFBFDE7000
heap
page read and write
E50000
heap
page read and write
384E000
stack
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFBFD72000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D38000
trusted library allocation
page read and write
9C5000
unkown
page readonly
3448000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
BDB000
stack
page read and write
1EFBFDE3000
heap
page read and write
9E8000
unkown
page readonly
1EFC1D41000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
FA0000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
3394000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
D77000
heap
page read and write
F4F000
heap
page read and write
1390000
unkown
page read and write
1050000
heap
page read and write
3620000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
571000
unkown
page execute read
1EFC1D45000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1020000
heap
page read and write
E3E000
stack
page read and write
5D8000
unkown
page readonly
1EFBFDA3000
heap
page read and write
3391000
trusted library allocation
page read and write
5B5000
unkown
page readonly
1049000
heap
page read and write
1EFC1D47000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
9C5000
unkown
page readonly
9E2000
unkown
page write copy
2E1B000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
3720000
heap
page read and write
F38000
heap
page read and write
1EFBFDE7000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
D9E000
heap
page read and write
38D0000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1001000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
3270000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
D98000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
402F000
stack
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
6F8E8000
unkown
page readonly
1EFC1D41000
trusted library allocation
page read and write
38D1000
heap
page read and write
3440000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D31000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
981000
unkown
page execute read
1EFC1CE0000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
3160000
heap
page read and write
2DB0000
trusted library section
page read and write
1EFC1D3F000
trusted library allocation
page read and write
31A5000
stack
page read and write
1EFBFDCE000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
13C0000
heap
page read and write
C90000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
B9C000
stack
page read and write
13A0000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFDE5000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
5B5000
unkown
page readonly
1EFC1D45000
trusted library allocation
page read and write
F73000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
F82000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
3545000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
31B0000
heap
page read and write
1EFBFDA3000
heap
page read and write
F40000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
2F70000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
3392000
trusted library allocation
page read and write
3730000
heap
page read and write
1EFBFDCE000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
3510000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
2DA0000
trusted library section
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFDE6000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1B60000
heap
page read and write
E8E000
stack
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
EFB000
stack
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1338000
stack
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1060000
heap
page read and write
1EFBFDA3000
heap
page read and write
412F000
stack
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
F6C000
heap
page read and write
F82000
heap
page read and write
1EFBFDE3000
heap
page read and write
1041000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
D00000
heap
page read and write
1EFC1A00000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDCB000
heap
page read and write
D9C000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
570000
unkown
page readonly
F58000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
32B8000
heap
page read and write
1EFBFDF7000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
9E2000
unkown
page write copy
1EFBFDCD000
heap
page read and write
31F0000
trusted library section
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFD58000
heap
page read and write
3610000
heap
page read and write
1EFBFDE7000
heap
page read and write
2F10000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D48000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
89D7DFE000
stack
page read and write
1EFBFF94000
trusted library allocation
page read and write
D29000
heap
page read and write
6F8C1000
unkown
page execute read
6F8C0000
unkown
page readonly
339B000
trusted library allocation
page read and write
1048000
heap
page read and write
104D000
heap
page read and write
89D79CF000
stack
page read and write
6CBC0000
unkown
page readonly
1EFBFDCD000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1060000
heap
page read and write
1050000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1050000
heap
page read and write
3520000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFD7D000
heap
page read and write
F20000
heap
page read and write
3020000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
3270000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
2CE0000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
39D0000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
112F000
stack
page read and write
3270000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
2D90000
trusted library section
page read and write
1EFBFDE7000
heap
page read and write
FE8000
heap
page read and write
6F8DA000
unkown
page readonly
1EFBFDE3000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1055000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
D52000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
3EEF000
stack
page read and write
1EFBFDE3000
heap
page read and write
981000
unkown
page execute read
1EFC1D3F000
trusted library allocation
page read and write
1022000
heap
page read and write
6F8E4000
unkown
page read and write
29CF000
stack
page read and write
1EFBFDCB000
heap
page read and write
9F0000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
30AC000
stack
page read and write
1EFBFDE7000
heap
page read and write
1EFBFDF7000
heap
page read and write
2CF0000
trusted library allocation
page read and write
F82000
heap
page read and write
3400000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
E80000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
CD8000
stack
page read and write
F71000
heap
page read and write
1EFBFDE7000
heap
page read and write
3710000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFDCD000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
2F40000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
FB6000
heap
page read and write
1EFBFD85000
heap
page read and write
320C000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDF9000
heap
page read and write
1EFBFDF8000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
DD0000
heap
page read and write
9E2000
unkown
page read and write
1EFC1D33000
trusted library allocation
page read and write
950000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
D44000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
5D8000
unkown
page readonly
1EFC1D4F000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
3B1A000
stack
page read and write
1EFC1D47000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
98C000
stack
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1045000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
402F000
stack
page read and write
1EFBFD85000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
3400000
trusted library allocation
page read and write
1EFBFD95000
heap
page read and write
3040000
heap
page read and write
1EFBFD85000
heap
page read and write
313E000
heap
page read and write
31BC000
heap
page read and write
33AC000
stack
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
3400000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
5D2000
unkown
page write copy
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
335B000
stack
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
331E000
stack
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
FE0000
heap
page read and write
1EFBFDCF000
heap
page read and write
89D794E000
stack
page read and write
30B8000
heap
page read and write
2CE0000
heap
page read and write
3398000
trusted library allocation
page read and write
3CE0000
heap
page read and write
1EFBFDD3000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
104E000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDD1000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDDF000
heap
page read and write
1EFBFDA1000
heap
page read and write
3BCF000
stack
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1060000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
3CF1000
heap
page read and write
CF0000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
452E000
stack
page read and write
1EFC1D3C000
trusted library allocation
page read and write
3B20000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFBFDD3000
heap
page read and write
9E2000
unkown
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFD10000
heap
page read and write
3DF0000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
3F2F000
stack
page read and write
FD8000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
3140000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
F73000
heap
page read and write
3396000
trusted library allocation
page read and write
5D8000
unkown
page readonly
1EFBFDE3000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
F61000
heap
page read and write
3122000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
570000
unkown
page readonly
1EFC1D40000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D32000
trusted library allocation
page read and write
1EFBFDF7000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D39000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1013000
heap
page read and write
1EFBFDCE000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
5DC000
stack
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
D98000
heap
page read and write
1EFBFDA3000
heap
page read and write
DF0000
heap
page read and write
1EFBFDA1000
heap
page read and write
D44000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDCD000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
2CE2000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
2B43000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
3790000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
3270000
trusted library allocation
page read and write
1EFBFDCD000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFDF8000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFDE0000
heap
page read and write
D92000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D4B000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFBFD7D000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
3440000
heap
page read and write
1EFBFD85000
heap
page read and write
5D2000
unkown
page write copy
3395000
trusted library allocation
page read and write
3397000
trusted library allocation
page read and write
388E000
stack
page read and write
1EFBFDCC000
heap
page read and write
F82000
heap
page read and write
1EFC1D4A000
trusted library allocation
page read and write
940000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFDF8000
heap
page read and write
D1C000
heap
page read and write
2DD0000
heap
page read and write
CFB000
stack
page read and write
1EFBFDE3000
heap
page read and write
3380000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
571000
unkown
page execute read
31C0000
heap
page read and write
1EFC1D4E000
trusted library allocation
page read and write
392E000
heap
page read and write
1EFC19C0000
heap
page read and write
2E70000
heap
page read and write
1EFBFDE3000
heap
page read and write
36AC000
stack
page read and write
F82000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
C96000
heap
page read and write
E00000
heap
page read and write
34CC000
stack
page read and write
5B5000
unkown
page readonly
31D0000
trusted library section
page read and write
105B000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
5D2000
unkown
page read and write
1EFBFD00000
heap
page read and write
980000
unkown
page readonly
1EFC1D42000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
A9C000
stack
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
2F3E000
heap
page read and write
1EFBFD7D000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDCD000
heap
page read and write
32B0000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
3393000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
F82000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFC1B74000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
3290000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFD30000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
FA0000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
F71000
heap
page read and write
1EFC18D0000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFBFDE2000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
981000
unkown
page execute read
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDCD000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFC1B70000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFDE5000
heap
page read and write
1EFBFD95000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1060000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
FF8000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
D77000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
D74000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
32DD000
stack
page read and write
1EFC18F0000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
339E000
trusted library allocation
page read and write
1EFBFD95000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDCB000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFBFDE7000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
3430000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFBFDE7000
heap
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
339A000
trusted library allocation
page read and write
1EFC1D36000
trusted library allocation
page read and write
9E8000
unkown
page readonly
1EFC1D41000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1020000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
F73000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFBFDA1000
heap
page read and write
3442000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
3110000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFD50000
heap
page read and write
1EFC1D20000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFBFDCE000
heap
page read and write
1059000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDD3000
heap
page read and write
3120000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
3400000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D4D000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
3270000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
571000
unkown
page execute read
6CBE7000
unkown
page read and write
350B000
stack
page read and write
1EFBFF90000
trusted library allocation
page read and write
1058000
heap
page read and write
D6A000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFDF7000
heap
page read and write
2ADC000
stack
page read and write
1EFBFDCF000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
D52000
heap
page read and write
3360000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D34000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
2CD0000
heap
page read and write
D7F000
heap
page read and write
981000
unkown
page execute read
1EFBFDE3000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
F50000
heap
page read and write
3110000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D41000
trusted library allocation
page read and write
3070000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDE7000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
2F73000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1EFBFDCB000
heap
page read and write
F6C000
heap
page read and write
6F8E7000
unkown
page read and write
89D78CA000
stack
page read and write
1EFC1D42000
trusted library allocation
page read and write
1022000
heap
page read and write
1EFBFDCF000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFDE2000
heap
page read and write
339D000
trusted library allocation
page read and write
FB0000
heap
page read and write
339F000
trusted library allocation
page read and write
1013000
heap
page read and write
1EFC1D35000
trusted library allocation
page read and write
E90000
heap
page read and write
5D2000
unkown
page read and write
2E28000
stack
page read and write
1EFBFD85000
heap
page read and write
432F000
stack
page read and write
1EFBFDCD000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
3100000
heap
page read and write
1EFBFDE7000
heap
page read and write
2AE0000
heap
page read and write
980000
unkown
page readonly
1EFBFF94000
trusted library allocation
page read and write
8FB000
stack
page read and write
2F2C000
stack
page read and write
F71000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
3920000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFBFDE5000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
104D000
heap
page read and write
1EFBFDE7000
heap
page read and write
1EFBFDE7000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
F82000
heap
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
3270000
trusted library allocation
page read and write
1EFBFD87000
heap
page read and write
1041000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
89D7CFE000
stack
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
1350000
trusted library allocation
page read and write
C80000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
442F000
stack
page read and write
1EFBFDE3000
heap
page read and write
3518000
heap
page read and write
2B00000
heap
page read and write
1EFC1D37000
trusted library allocation
page read and write
3D71000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
1EFBFDCE000
heap
page read and write
F51000
heap
page read and write
3ACF000
stack
page read and write
1EFC1D49000
trusted library allocation
page read and write
9C5000
unkown
page readonly
1EFC1D3B000
trusted library allocation
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
2AF0000
unkown
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFC1D42000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
5B5000
unkown
page readonly
1EFC1D3E000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDA1000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFDCF000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFBFD95000
heap
page read and write
1EFC1D43000
trusted library allocation
page read and write
1058000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1EFC1D4C000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1023000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
1060000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
3BD7000
heap
page read and write
339C000
trusted library allocation
page read and write
1EFBFDE3000
heap
page read and write
104A000
heap
page read and write
1041000
heap
page read and write
1EFC1D3D000
trusted library allocation
page read and write
2D70000
heap
page read and write
3399000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFBFDCB000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
9E8000
unkown
page readonly
6CBE4000
unkown
page read and write
D08000
heap
page read and write
1010000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
6CBC1000
unkown
page execute read
1EFBFDF5000
heap
page read and write
980000
unkown
page readonly
1EFC1D3C000
trusted library allocation
page read and write
9E8000
unkown
page readonly
1EFBFD85000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
D42000
heap
page read and write
3512000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFD77000
heap
page read and write
1EFBFD85000
heap
page read and write
1EFBFDCE000
heap
page read and write
B10000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFFD5000
heap
page read and write
1EFBFDCD000
heap
page read and write
1EFBFF90000
trusted library allocation
page read and write
1060000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
3930000
trusted library allocation
page read and write
D9C000
heap
page read and write
1EFBFDE3000
heap
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFBFD85000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
D42000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFBFDCE000
heap
page read and write
571000
unkown
page execute read
2B40000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
35DE000
stack
page read and write
3400000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
FD0000
heap
page read and write
6CBDA000
unkown
page readonly
2D80000
heap
page read and write
F90000
heap
page read and write
3160000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
3F2E000
stack
page read and write
1EFBFDE3000
heap
page read and write
1EFBFD85000
heap
page read and write
F71000
heap
page read and write
1EFBFD77000
heap
page read and write
1EFBFDF9000
heap
page read and write
3CF0000
heap
page read and write
1EFBFDE3000
heap
page read and write
3270000
trusted library allocation
page read and write
1EFC1B7F000
heap
page read and write
980000
unkown
page readonly
1030000
heap
page read and write
1EFC1D3F000
trusted library allocation
page read and write
570000
unkown
page readonly
3200000
heap
page read and write
1015000
heap
page read and write
3E2D000
stack
page read and write
9C5000
unkown
page readonly
1EFBFDE3000
heap
page read and write
1EFBFFD0000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
3400000
trusted library allocation
page read and write
1EFBFDE7000
heap
page read and write
1023000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFBFF90000
trusted library allocation
page read and write
31E0000
trusted library section
page read and write
1EFC1D3B000
trusted library allocation
page read and write
1EFC1D3E000
trusted library allocation
page read and write
D87000
heap
page read and write
1EFBFD85000
heap
page read and write
3390000
trusted library allocation
page read and write
6CBE8000
unkown
page readonly
89D7D7E000
stack
page read and write
1EFBFDA3000
heap
page read and write
1EFC1D45000
trusted library allocation
page read and write
1EFC1D46000
trusted library allocation
page read and write
1EFC1D3A000
trusted library allocation
page read and write
13C6000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFDE3000
heap
page read and write
3270000
trusted library allocation
page read and write
1015000
heap
page read and write
1EFC1D3C000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
1EFC1D40000
trusted library allocation
page read and write
1EFBFDA3000
heap
page read and write
1030000
heap
page read and write
1EFC1D44000
trusted library allocation
page read and write
1EFC1D43000
trusted library allocation
page read and write
1EFC1D3D000
trusted library allocation
page read and write
570000
unkown
page readonly
1EFBFDA1000
heap
page read and write
3811000
heap
page read and write
1EFC1D42000
trusted library allocation
page read and write
D78000
heap
page read and write
1EFC1D3E000
trusted library allocation
page read and write
1EFC1D45000
trusted library allocation
page read and write
336C000
heap
page read and write
1EFC1D41000
trusted library allocation
page read and write
1EFBFDA1000
heap
page read and write
F30000
heap
page read and write
1EFBFDCE000
heap
page read and write
1EFBFDA3000
heap
page read and write
1EFBFF94000
trusted library allocation
page read and write
There are 1032 hidden memdumps, click here to show them.